<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:win-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:sol-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:hpux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" xmlns:linux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5">
  <generator>
    <oval:schema_version>5.1</oval:schema_version>
    <oval:timestamp>2007-01-04T10:42:07.384-05:00</oval:timestamp>
    <oval:product_name>The MITRE Corporation</oval:product_name>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:908" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
        <description>Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:02.185-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.7108" test_ref="oval:org.mitre.oval:tst:73"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of wkssvc.dll is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:842" version="1" class="vulnerability">
      <metadata>
        <title>MS Windows Media Service Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0905"/>
        <description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server">
            <criterion comment="Windows Media Services 4.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1602"/>
            <criteria operator="AND" comment="Windows 2000 Server is installed">
              <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
              <criteria operator="OR" comment="Windows NT server product option">
                <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
                <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="the version of nscm.exe is less than 4.1.0.3934" negate="false" test_ref="oval:org.mitre.oval:tst:1601"/>
          <criterion comment="the version of nspmon.exe is less than 4.1.0.3934" negate="false" test_ref="oval:org.mitre.oval:tst:1600"/>
          <criterion comment="the patch kb832359 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1599"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="configured to only offer streaming media over unicast" negate="true" test_ref="oval:org.mitre.oval:tst:1598"/>
          <criterion comment="the Windows Media Station service is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1597"/>
          <criterion comment="the Windows Media Monitor service is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:762" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft SharePoint Team Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:53:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SharePoint Team Services are enabled (2K, XP, 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2379"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:761" class="vulnerability" version="1">
      <metadata>
        <title>Script Error Handling Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5579" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5579"/>
        <description>Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:01.277-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" negate="false" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" negate="false" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3020" negate="false" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" negate="false" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:709" class="vulnerability" version="1">
      <metadata>
        <title>Flash Improper Memory Access Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3587"/>
        <description>Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.827-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="WinXP,SP2 or WinXP,SP1 (64-bit)" operator="OR">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
        </criteria>
        <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
          <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
          <criterion comment="Flash8.ocx  (minimum version 8.0.22.0) is not installed" test_ref="oval:org.mitre.oval:tst:83" negate="true"/>
          <criterion comment="Flash9.ocx  (minimum version 9.0.16.0) is not installed" test_ref="oval:org.mitre.oval:tst:85" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:675" version="1" class="vulnerability">
      <metadata>
        <title>MS Excel 97 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-14 - wft-14 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2434) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 97 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2435"/>
        <criterion comment="the version of excel.exe is less than 8.00.01.9904" negate="false" test_ref="oval:org.mitre.oval:tst:2434"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:669" class="vulnerability" version="1">
      <metadata>
        <title>Windows Media Format ASX Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6134"/>
        <description>Heap-based buffer overflow in the WMCheckURLScheme function in WMVCORE.DLL in Microsoft Windows Media Player (WMP) 10.00.00.4036 on Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long HREF attribute, using an unrecognized protocol, in a REF element in an ASX PlayList file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.223-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:102" comment="Wmvcore.dll for Windows Media Format 7.1 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:174" comment="the version of Wmvcore.dll is less than 7.10.0.3079"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:125" comment="Wmvcore.dll for Windows Media Format 9.0 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:112" comment="the version of Wmvcore.dll is less than 9.0.0.3265"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:521" comment="Windows XP, SP2 is installed"/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:191" comment="the version of Wmvcore.dll is less than 10.0.0.3702"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:2747" comment="a 64-bit version of Windows is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:117" comment="the version of Wmvcore.dll is less than 10.0.0.3810"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
          <criterion test_ref="oval:org.mitre.oval:tst:2747" negate="true" comment="a 64-bit version of Windows is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:116" comment="the version of Wmvcore.dll is less than 10.0.0.3708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:625" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:52:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows NT, 2000, or XP is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2677"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:607" class="vulnerability" version="1">
      <metadata>
        <title>Workstation Service Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4691"/>
        <description>Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:54:00.053-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.7108" test_ref="oval:org.mitre.oval:tst:73"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of wkssvc.dll is less than 5.1.2600.2976" test_ref="oval:org.mitre.oval:tst:113"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:586" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 98 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 98</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-16T04:13:00.000-04:00" comment="Modified test 2528 to use obj:492 rather than obj:1443 since they were the same and this definition was the only reference to obj:1443.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2006-10-16T04:13:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 98 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2529"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9716" negate="false" test_ref="oval:org.mitre.oval:tst:2528"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:585" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 97 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-17 - wft-17 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T12:01:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-20T12:00:00.000-04:00" comment="Corrected unknown test">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 97 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2531"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9315" negate="false" test_ref="oval:org.mitre.oval:tst:2530"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:560" class="vulnerability" version="1">
      <metadata>
        <title>File Manifest Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5585"/>
        <description>The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest within an application, aka "File Manifest Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.700-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Sxs.dll is less than 5.1.2600.3019" test_ref="oval:org.mitre.oval:tst:137"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Sxs.dll is less than 5.2.3790.599" test_ref="oval:org.mitre.oval:tst:123"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:538" class="vulnerability" version="1">
      <metadata>
        <title>Excel-Flash Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3014"/>
        <description>Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.493-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="WinXP,SP2 or WinXP,SP1 (64-bit)" operator="OR">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
        </criteria>
        <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
          <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
          <criterion comment="Flash8.ocx  (minimum version 8.0.22.0) is not installed" test_ref="oval:org.mitre.oval:tst:83" negate="true"/>
          <criterion comment="Flash9.ocx  (minimum version 9.0.16.0) is not installed" test_ref="oval:org.mitre.oval:tst:85" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:536" class="vulnerability" version="1">
      <metadata>
        <title>Windows Media Format ASF Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4702"/>
        <description>Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.278-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:100" comment="Media Player 8 (v6.4) is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:96" comment="the version of dxmasf.dll is less than 6.4.9.1133"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:102" comment="Wmvcore.dll for Windows Media Format 7.1 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:174" comment="the version of Wmvcore.dll is less than 7.10.0.3079"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:125" comment="Wmvcore.dll for Windows Media Format 9.0 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:112" comment="the version of Wmvcore.dll is less than 9.0.0.3265"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:521" comment="Windows XP, SP2 is installed"/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:191" comment="the version of Wmvcore.dll is less than 10.0.0.3702"/>
        </criteria>
        <criteria operator="AND">
          <criterion test_ref="oval:org.mitre.oval:tst:2747" comment="a 64-bit version of Windows is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:117" comment="the version of Wmvcore.dll is less than 10.0.0.3810"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
          <criterion test_ref="oval:org.mitre.oval:tst:2747" negate="true" comment="a 64-bit version of Windows is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:115" comment="Wmvcore.dll for Windows Media Format 9.5 is installed."/>
          <criterion test_ref="oval:org.mitre.oval:tst:116" comment="the version of Wmvcore.dll is less than 10.0.0.3708"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:477" version="1" class="vulnerability">
      <metadata>
        <title>MS Exchange / OWA NTLM Authentication Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0904"/>
        <description>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1480 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Exchange Server 2003 (gold edition) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2760"/>
          <criterion comment="the version of exprox.dll is less than 6.5.6980.57" negate="false" test_ref="oval:org.mitre.oval:tst:2605"/>
          <criterion comment="the patch KB832759 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2604"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="this is a front-end server providing Outlook Web Access" negate="false" test_ref="oval:org.mitre.oval:tst:2603"/>
          <criterion comment="the back-end server is Exchange Server 2003 running on Windows 2003" negate="false" test_ref="oval:org.mitre.oval:tst:2602"/>
          <criterion comment="HTTP connection reuse is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:2601"/>
          <criterion comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" negate="false" test_ref="oval:org.mitre.oval:tst:2600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:456" class="vulnerability" version="1">
      <metadata>
        <title>HTML Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4687"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via crafted layout combinations involving DIV tags and HTML CSS float properties that trigger memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:57.976-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.594" negate="false" test_ref="oval:org.mitre.oval:tst:71"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2795" negate="false" test_ref="oval:org.mitre.oval:tst:70"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2995" negate="false" test_ref="oval:org.mitre.oval:tst:66"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1578" negate="false" test_ref="oval:org.mitre.oval:tst:65"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4 (disagrees with bulletin, but needed to match MBSA results)" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:437" class="vulnerability" version="1">
      <metadata>
        <title>DirectAnimation ActiveX Controls Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4446" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4446"/>
        <description>Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument specifies a large number of points.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:57.418-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.594" negate="false" test_ref="oval:org.mitre.oval:tst:71"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2795" negate="false" test_ref="oval:org.mitre.oval:tst:70"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2995" negate="false" test_ref="oval:org.mitre.oval:tst:66"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1578" negate="false" test_ref="oval:org.mitre.oval:tst:65"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:432" class="vulnerability" version="1">
      <metadata>
        <title>Malformed, Compressed .swf File Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3588" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3588"/>
        <description>Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to cause a denial of service (browser crash) via a malformed, compressed .swf file, a different issue than CVE-2006-3587.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:57.009-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="WinXP,SP2 or WinXP,SP1 (64-bit)" operator="OR">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
        </criteria>
        <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
          <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
          <criterion comment="Flash8.ocx  (minimum version 8.0.22.0) is not installed" test_ref="oval:org.mitre.oval:tst:83" negate="true"/>
          <criterion comment="Flash9.ocx  (minimum version 9.0.16.0) is not installed" test_ref="oval:org.mitre.oval:tst:85" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:419" version="2">
      <metadata>
        <title>.NET 2.0 Application Folder Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>.NET Framework</product>
        </affected>
        <reference ref_id="CVE-2006-1300" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1300" source="CVE"/>
        <description>Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:24.125-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:39.673-04:00">ACCEPTED</status_change>
            <modified comment="Corrected comment on tst:8. Added new state ste:98 to check the correct file version. Corrected file path and name specification in obj:180. Edits made by Jon Baker." date="2006-11-09T06:09:00.371-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2007-01-04T09:13:47.443-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The .NET Framework v2.0 is installed" definition_ref="oval:org.mitre.oval:def:310"/>
        <criterion comment="the version of Aspnet_filter.dll is less than 2.0.50727.101" test_ref="oval:org.mitre.oval:tst:8"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:413" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4689"/>
        <description>Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.587-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of nwrdr.sys is less than 5.0.2195.7110" test_ref="oval:org.mitre.oval:tst:74"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of nwrdr.sys is less than 5.1.2600.3015" test_ref="oval:org.mitre.oval:tst:75"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of nwrdr.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:84"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of nwrdr.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:76"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:404" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Client Service for NetWare Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4688"/>
        <description>Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.358-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of nwrdr.sys is less than 5.0.2195.7110" test_ref="oval:org.mitre.oval:tst:74"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of nwrdr.sys is less than 5.1.2600.3015" test_ref="oval:org.mitre.oval:tst:75"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="The version of nwrdr.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:84"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of nwrdr.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:76"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:394" class="vulnerability" version="1">
      <metadata>
        <title>SWF Movie Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3311" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3311"/>
        <description>Buffer overflow in Adobe Flash Player 8.0.24.0 and earlier, Flash Professional 8, Flash MX 2004, and Flex 1.5 allows user-assisted remote attackers to execute arbitrary code via a long, dynamically created string in a SWF movie.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:55.781-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="WinXP,SP2 or WinXP,SP1 (64-bit)" operator="OR">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
        </criteria>
        <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
          <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
          <criterion comment="Flash8.ocx  (minimum version 8.0.22.0) is not installed" test_ref="oval:org.mitre.oval:tst:83" negate="true"/>
          <criterion comment="Flash9.ocx  (minimum version 9.0.16.0) is not installed" test_ref="oval:org.mitre.oval:tst:85" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:375" class="vulnerability" version="1">
      <metadata>
        <title>RIS Writable Path Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5584"/>
        <description>The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:55.046-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Win2K,SP4" operator="AND">
        <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="The TFTP Service is activated." test_ref="oval:org.mitre.oval:tst:177"/>
        <criterion comment="The RIS Server has been set to prevent unauthorized access." negate="true" test_ref="oval:org.mitre.oval:tst:197"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3465" version="1" class="vulnerability">
      <metadata>
        <title>SunOS 5.9: ufs and fsck patch</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Solaris Volume Manager (SVM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1346"/>
        <description>The Sun Solaris Volume Manager (SVM) on Solaris 9 allows local users to cause a denial of service (kernel panic) via a malformed probe request to the SVM.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T05:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected operation on line element of textfilecontent_object. Operation must be pattern match." date="2007-01-04T08:52:00.308-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T08:54:46.519-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Patch 113073-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:426"/>
          <criterion comment="Solaris Volume Manager package installed" negate="false" test_ref="oval:org.mitre.oval:tst:425"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="svm.init init script exists" negate="false" test_ref="oval:org.mitre.oval:tst:424"/>
          <criterion comment="/etc/vfstab is configured with SVM devices" negate="false" test_ref="oval:org.mitre.oval:tst:423"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:337" class="vulnerability" version="1">
      <metadata>
        <title>TIF Folder Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5578" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5578"/>
        <description>Microsoft Internet Explorer 6 and earlier allows remote attackers to read Temporary Internet Files (TIF) and obtain sensitive information via unspecified vectors involving certain drag and drop operations, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5577.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:53.907-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" negate="false" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" negate="false" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3020" negate="false" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" negate="false" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3846.2300" negate="false" test_ref="oval:org.mitre.oval:tst:88"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:313" class="vulnerability" version="1">
      <metadata>
        <title>TIF Folder Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5577" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5577"/>
        <description>Microsoft Internet Explorer 6 and earlier allows remote attackers to obtain sensitive information via unspecified uses of the OBJECT HTML tag, which discloses the absolute path of the corresponding TIF folder, aka "TIF Folder Information Disclosure Vulnerability," and a different issue than CVE-2006-5578.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:53.175-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" negate="false" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" negate="false" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3020" negate="false" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" negate="false" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3846.2300" negate="false" test_ref="oval:org.mitre.oval:tst:88"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:426" class="inventory" version="1">
      <metadata>
        <title>Microsoft Visual Studio 2005 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft Visual Studio 2005 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.869-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visual Studio 2005 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:288" class="vulnerability" version="1">
      <metadata>
        <title>WMI Object Broker Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Visual Studio</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4704"/>
        <description>Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:52.674-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Microsoft Visual Studio 2005 is installed." definition_ref="oval:org.mitre.oval:def:426"/>
        <criterion comment="The version of WmiScriptUtils.dll is less than 8.0.50727.236." test_ref="oval:org.mitre.oval:tst:150"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2204" version="1" class="vulnerability">
      <metadata>
        <title>IIS4.0 Redirect Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0205"/>
        <description>Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected datatype of value element on ste:536. Datatype should be int" date="2007-01-04T09:00:00.815-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T09:01:32.938-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the patch q841373 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:595"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.788.1" negate="false" test_ref="oval:org.mitre.oval:tst:594"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Permanent redirects enabled" negate="false" test_ref="oval:org.mitre.oval:tst:593"/>
          <criterion comment="MaxClientRequestBufferData less than or equal to 16384" negate="true" test_ref="oval:org.mitre.oval:tst:592"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1583" version="1" class="vulnerability">
      <metadata>
        <title>Win2K Kernel Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2827" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2827"/>
        <description>The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Changed obj:633 to use var:200 to get the Windows System 32 directory." date="2007-01-04T08:58:00.479-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T09:00:02.619-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="The version of Ntkrnlpa.exe is less than 5.0.2195.7071" negate="false" test_ref="oval:org.mitre.oval:tst:839"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:154" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft Agent Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3445" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3445"/>
        <description>Microsoft Agent on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted .ACF file that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:49.969-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1242" test_ref="oval:org.mitre.oval:tst:109"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3424" test_ref="oval:org.mitre.oval:tst:195"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1242" test_ref="oval:org.mitre.oval:tst:109"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1436" version="1" class="vulnerability">
      <metadata>
        <title>Solaris CDE DTLogin XDMCP Parser Remote Double Free Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0368" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0368"/>
        <description>Double-free vulnerability in dtlogin in CDE on Solaris, HP-UX, and other operating systems allows remote attackers to execute arbitrary code via a crafted XDMCP packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-12T12:47:00.000-04:00" comment="Added patch 107180-31 test for Solaris 7.  Changed vulnerable software test logic a little">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected datatype on base element. Datatype must be int." date="2007-01-04T08:54:00.038-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T08:56:47.173-05:00">INTERIM</status_change>
            <modified comment="Corrected datatype on version element in ste:841. Datatype must be int." date="2007-01-04T09:48:00.458-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File /usr/dt/bin/dtlogin exists" negate="false" test_ref="oval:org.mitre.oval:tst:939"/>
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 108919-21 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:937"/>
          <criterion comment="Patch 112807-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:936"/>
          <criterion comment="Patch 107180-31 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:935"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="dtlogin running" negate="false" test_ref="oval:org.mitre.oval:tst:938"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1273" version="1" class="vulnerability">
      <metadata>
        <title>Solaris SAdmin Client Credentials Remote Administrative Access Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sadmin</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0722"/>
        <description>The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T02:06:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-15T02:21:00.000-04:00" comment="Added check for sadmind called with strong authentication">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Corrected datatype on version element of patch state. Datatype must be int." date="2007-01-04T08:56:00.454-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-04T08:58:16.556-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="System and Network Administration Framework Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1024"/>
          <criterion comment="Patch 116457-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1022"/>
          <criterion comment="Patch 116442-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1021"/>
          <criterion comment="Patch 116454-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1020"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains sadmind" negate="false" test_ref="oval:org.mitre.oval:tst:1023"/>
          <criterion comment="Sadmin called using strong authentication" negate="true" test_ref="oval:org.mitre.oval:tst:1019"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:116" class="vulnerability" version="1">
      <metadata>
        <title>DHTML Script Function Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5581" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5581"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via certain DHTML script functions, such as normalize, and "incorrectly created elements" that trigger memory corruption, aka "DHTML Script Function Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:48.603-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.605" negate="false" test_ref="oval:org.mitre.oval:tst:92"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2817" negate="false" test_ref="oval:org.mitre.oval:tst:90"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.3020" negate="false" test_ref="oval:org.mitre.oval:tst:132"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1586" negate="false" test_ref="oval:org.mitre.oval:tst:89"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1103" class="vulnerability" version="1">
      <metadata>
        <title>DirectAnimation ActiveX Controls Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4777" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4777"/>
        <description>Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:48.307-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.594" negate="false" test_ref="oval:org.mitre.oval:tst:71"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2795" negate="false" test_ref="oval:org.mitre.oval:tst:70"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2995" negate="false" test_ref="oval:org.mitre.oval:tst:66"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1578" negate="false" test_ref="oval:org.mitre.oval:tst:65"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:142"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:504" class="inventory" version="1">
      <metadata>
        <title>Outlook Express 5.5 SP2 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <description>Outlook Express 5.5 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:59.147-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Outlook Express 5.5 SP2 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:488" class="inventory" version="1">
      <metadata>
        <title>Outlook Express 6 SP1 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Outlook Express 6 SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:58.863-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Outlook Express 6 SP1 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:425" class="inventory" version="1">
      <metadata>
        <title>Outlook Express 6 is installed.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Outlook Express 6 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:56.756-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Outlook Express 6 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <extend_definition comment="Outlook Express 6 SP1 is installed." negate="true" definition_ref="oval:org.mitre.oval:def:488"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1055" class="vulnerability" version="1">
      <metadata>
        <title>Windows Address Book Contact Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2386" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2386"/>
        <description>Unspecified vulnerability in Microsoft Outlook Express 6 and earlier allows remote attackers to execute arbitrary code via a crafted contact record in a Windows Address Book (WAB) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.933-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Outlook Express 5.5, SP2 is installed" definition_ref="oval:org.mitre.oval:def:504"/>
          <criterion comment="the version of inetcomm.dll is less than 5.50.4971.600" test_ref="oval:org.mitre.oval:tst:134"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Outlook Express 6, SP1 is installed" definition_ref="oval:org.mitre.oval:def:488"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1896" test_ref="oval:org.mitre.oval:tst:143"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Outlook Express 6 is installed" definition_ref="oval:org.mitre.oval:def:425"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.3028" test_ref="oval:org.mitre.oval:tst:145"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Outlook Express 6 is installed" definition_ref="oval:org.mitre.oval:def:425"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2826" test_ref="oval:org.mitre.oval:tst:146"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Outlook Express 6 is installed" definition_ref="oval:org.mitre.oval:def:425"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.607" test_ref="oval:org.mitre.oval:tst:148"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="Outlook Express 6 is installed" definition_ref="oval:org.mitre.oval:def:425"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2826" test_ref="oval:org.mitre.oval:tst:146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1050" class="vulnerability" version="1">
      <metadata>
        <title>Flash Arbitrary Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3587"/>
        <description>Unspecified vulnerability in Adobe (Macromedia) Flash Player 8.0.24.0 allows remote attackers to execute arbitrary commands via a malformed .swf file that results in "multiple improper memory access" errors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.670-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="WinXP,SP2 or WinXP,SP1 (64-bit)" operator="OR">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
        </criteria>
        <criteria comment="Flash.ocx exists without upgrades to Flash8 or Flash9" operator="AND">
          <criterion comment="Flash.ocx exists" test_ref="oval:org.mitre.oval:tst:79"/>
          <criterion comment="Flash8.ocx  (minimum version 8.0.22.0) is not installed" test_ref="oval:org.mitre.oval:tst:83" negate="true"/>
          <criterion comment="Flash9.ocx  (minimum version 9.0.16.0) is not installed" test_ref="oval:org.mitre.oval:tst:85" negate="true"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1047" class="vulnerability" version="1">
      <metadata>
        <title>SNMP Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5583" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5583"/>
        <description>Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-12-13T08:17:04">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-12-14T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.448-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Snmp.exe is less than 5.0.2195.7112" test_ref="oval:org.mitre.oval:tst:118"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Snmp.exe is less than 5.1.2600.3038" test_ref="oval:org.mitre.oval:tst:119"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Snmp.exe is less than 5.2.3790.2837" test_ref="oval:org.mitre.oval:tst:120"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Snmp.exe is less than 5.2.3790.615" test_ref="oval:org.mitre.oval:tst:121"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Snmp.exe is less than 5.2.3790.2837" test_ref="oval:org.mitre.oval:tst:120"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:104" class="vulnerability" version="1">
      <metadata>
        <title>Microsoft XML Core Services Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5745"/>
        <description>Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685.  NOTE: some of these details are obtained from third party information.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-11-15T12:28:05">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-11-17T12:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-01-03T13:53:47.020-05:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
          <criterion comment="The version of Msxml4.dll is less than 4.20.9841.0" negate="false" test_ref="oval:org.mitre.oval:tst:62"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criterion comment="The version of Msxml6.dll is less than 6.0.3890.0" negate="false" test_ref="oval:org.mitre.oval:tst:138"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1036" version="1" class="vulnerability">
      <metadata>
        <title>Veritas Backup Exec RestrictAnonymous Forced Misconfiguration Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Veritas Backup Exec 8.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1117"/>
        <description>Veritas Backup Exec 8.5 and earlier requires that the "RestrictAnonymous" registry key for Microsoft Exchange 2000 must be set to 0, which enables anonymous listing of the SAM database and shares.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-472 - wrt-472 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Affected bkupexec.exe versions 3.60.1.298" negate="false" test_ref="oval:org.mitre.oval:tst:1271"/>
          <criterion comment="Veritas Backup Exec 8.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1270"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RestrictAnonymous registry value allows anonymous connections" negate="false" test_ref="oval:org.mitre.oval:tst:1269"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:957" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-09-27T11:12:00.000-04:00" comment="modified wft-199 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists on Server 2003">
            <criteria operator="AND" comment="32-bit machine a vulnerable version of rpcss.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists on non 64-bit Server 2003">
                <criterion comment="machine has followed the GDR update path and rpcss.dll is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1403"/>
                <criterion comment="machine has followed the QFE update path and rpcss.dll is less than 5.2.3790.142" negate="false" test_ref="oval:org.mitre.oval:tst:1402"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit machine and rpcss.dll is less than 5.2.3790.146">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of rpcss.dll is less than 5.2.3790.142" negate="false" test_ref="oval:org.mitre.oval:tst:1401"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:894" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 RPCSS DCOM Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of rpcrt4.dll exists on Server 2003">
          <criterion comment="machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137" negate="false" test_ref="oval:org.mitre.oval:tst:1498"/>
          <criterion comment="machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141" negate="false" test_ref="oval:org.mitre.oval:tst:1497"/>
        </criteria>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4226" version="1" class="vulnerability">
      <metadata>
        <title>Excel 2002 File Handler Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0846"/>
        <description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-18T12:11:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1377 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2420"/>
        <criterion comment="Service Pack 2 or less for Windows Office XP" negate="false" test_ref="oval:org.mitre.oval:tst:340"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3606" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail Ruleset Parsing Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0681"/>
        <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:26:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Sendmail - root (SUNWsndmr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:608"/>
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 107684-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:392"/>
          <criterion comment="Patch 110615-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:391"/>
          <criterion comment="Patch 113575-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:464"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Sendmail running" negate="false" test_ref="oval:org.mitre.oval:tst:583"/>
          <criterion comment="Sendmail has recipient or final rulesets" negate="false" test_ref="oval:org.mitre.oval:tst:393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2665" version="1" class="vulnerability">
      <metadata>
        <title>Data Leak in NIC</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Sun Am7990 Ethernet Driver</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0001"/>
        <description>Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 112604-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:497"/>
          <criterion comment="Patch 112609-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:496"/>
          <criterion comment="Patch 115172-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:495"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Lance Ethernet (le) interface configured to start" negate="false" test_ref="oval:org.mitre.oval:tst:494"/>
          <criterion comment="Lance Ethernet interface in use" negate="false" test_ref="oval:org.mitre.oval:tst:493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2426" version="1" class="vulnerability">
      <metadata>
        <title>BSM Audit Kernel Panic</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Basic Security Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0654" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0654"/>
        <description>Unknown vulnerability in the Basic Security Module (BSM), when configured to audit either the Administrative (ad) or the System-Wide Administration (as) audit class in Solaris 7, 8, and 9, allows local users to cause a denial of service (kernel panic).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T09:40:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Patch 106541-33 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:542"/>
          <criterion comment="Patch 109007-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:541"/>
          <criterion comment="Patch 114332-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:540"/>
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Basic Security Module enabled" negate="false" test_ref="oval:org.mitre.oval:tst:539"/>
          <criterion comment="Auditing Administrative or System-Wide Administrative audit classes" negate="false" test_ref="oval:org.mitre.oval:tst:538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1157" version="1" class="vulnerability">
      <metadata>
        <title>Crystal Reports Business Objects Directory Traversal</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Crystal Enterprise</product>
          <product>Crystal Reports</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0204" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0204"/>
        <description>Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and other products, allows remote attackers to read and delete arbitrary files via ".." sequences in the dynamicimag argument to crystalimagehandler.aspx.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-01-18T12:00:00.000-04:00" comment="modified wrt-400 - Changed datatype to int was incorrectly set to binary">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
          </dates>
          <status>DRAFT</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" negate="false" test_ref="oval:org.mitre.oval:tst:1113"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the w3svc service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1112"/>
          <criterion comment="a website linked to the Crystal Reports Viewer is active" negate="false" test_ref="oval:org.mitre.oval:tst:1111"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:999" version="2">
      <metadata>
        <title>Hyperlink Object Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3086" source="CVE"/>
        <description>Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:41.883-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.665-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.560" test_ref="oval:org.mitre.oval:tst:114"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:998" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Xorg Privilege Escalation via Pixmaps Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-12T01:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 9 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118908-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1337"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86,Xorg) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 118966-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1335"/>
            <criterion comment="File Xorg exists" negate="false" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="The Xorg X server is running" negate="false" test_ref="oval:org.mitre.oval:tst:1334"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:997" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise Linux 3 Kernel Serial Link Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461"/>
        <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kernel version is less than 2.4.21-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1342"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/proc/tty/driver/serial is world-readable" negate="false" test_ref="oval:org.mitre.oval:tst:1341"/>
          <criterion comment="/proc/tty/driver/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1340"/>
          <criterion comment="/proc/tty/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1339"/>
          <criterion comment="/proc/ is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:1338"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:996" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Share Level Password Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <product>File and Print Sharing</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0979"/>
        <description>File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:32:00.000-04:00" comment="modified wft-337 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 98 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1345"/>
        <criterion comment="File %windir%\system\vserver.vxd version is less than 4.10.2001.0" negate="false" test_ref="oval:org.mitre.oval:tst:1344"/>
        <criterion comment="Patch 273991USA8.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1343"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:995" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807"/>
        <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-18T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-02T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcproxy.dll is less than 5.0.2195.6904" negate="false" test_ref="oval:org.mitre.oval:tst:1346"/>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="COM Internet Services are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:994" version="1" class="vulnerability">
      <metadata>
        <title>CVS error_prog_name Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0416"/>
        <description>Double-free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:993" version="1" class="vulnerability">
      <metadata>
        <title>CVS Improper Handling of Malformed Entry Lines</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0414"/>
        <description>CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:992" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Core Stack Size DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3295"/>
        <description>Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-31T12:19:00.000-04:00" comment="Updated reference to CVE-2005-3295.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.943-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.CORE2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1350"/>
        <criteria operator="OR" comment="Either PHKL_33713 or PHKL_33714 or later is installed" negate="true">
          <criterion comment="Patch PHKL_33713 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1349"/>
          <criterion comment="Patch PHKL_33714 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1348"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:991" version="1" class="vulnerability">
      <metadata>
        <title>Mutliple BO Vulnerabilities in MIT Kerberos 5</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>MIT Kerberos 5 (krb5)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="krb5-libs rpm version prior to 1.2.7-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1351"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:990" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6.0 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1353"/>
        <criterion comment="the version of inetcomm.dll is less than 6.00.2739.300" negate="false" test_ref="oval:org.mitre.oval:tst:1352"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:99" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0 Content Disposition/Type Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0193"/>
        <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-03-07T05:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:41.221-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:3086"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:989" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express 6,SP1 News Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1213"/>
        <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1506" negate="false" test_ref="oval:org.mitre.oval:tst:1354"/>
        <criterion comment="Patch KB897715 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:988" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal MMSE Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0507"/>
        <description>Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:987" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0506" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0506"/>
        <description>The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:986" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal AIM Dissector Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0505" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0505"/>
        <description>The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:985" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Call Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:984" version="1" class="vulnerability">
      <metadata>
        <title>Racoon Denial of Service via Large Length Field</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0403" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0403"/>
        <description>Racoon before 20040408a allows remote attackers to cause a denial of service (memory consumption) via an ISAKMP packet with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:983" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS 5.1 Minor Version" negate="false" test_ref="oval:org.mitre.oval:tst:1357"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" negate="false" test_ref="oval:org.mitre.oval:tst:1356"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:982" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal Denial of Service via SIP Messages</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0504" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0504"/>
        <description>Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1359"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.2" negate="false" test_ref="oval:org.mitre.oval:tst:1358"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:980" version="1" class="vulnerability">
      <metadata>
        <title>NTLM Authentication BO in Squid Web Proxy Cache</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0541"/>
        <description>Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="squid version is less than 2.5.STABLE3-6.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1361"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1360"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:98" version="1" class="vulnerability">
      <metadata>
        <title>Gopher Client Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0371"/>
        <description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" negate="false" test_ref="oval:org.mitre.oval:tst:2945"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Gopher Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2944"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:979" version="1" class="vulnerability">
      <metadata>
        <title>Utempter Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0233"/>
        <description>Utempter allows device names that contain .. (dot dot) directory traversal sequences, which allows local users to overwrite arbitrary files via a symlink attack on device names in combination with an application that trusts the utmp or wtmp files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="utempter version is less than 0.5.5-1.3EL.0" negate="false" test_ref="oval:org.mitre.oval:tst:1366"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/sbin/utempter is executable">
            <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1365"/>
            <criteria operator="OR" comment="/usr/sbin/utempter is executable">
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1364"/>
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1363"/>
              <criterion comment="/usr/sbin/utempter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1362"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:978" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Directory Traversal Vulnerabilities in LHA</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0235" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0235"/>
        <description>Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="lha version is less than 1.14i-10.2" negate="false" test_ref="oval:org.mitre.oval:tst:1370"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/lha is executable">
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1369"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1368"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1367"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:977" version="1" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in LHA get_header Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0234" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0234"/>
        <description>Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="lha version is less than 1.14i-10.2" negate="false" test_ref="oval:org.mitre.oval:tst:1370"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/lha is executable">
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1369"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1368"/>
            <criterion comment="/usr/bin/lha is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1367"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:976" version="1" class="vulnerability">
      <metadata>
        <title>tcpdump Identification Payload in ISAKMP Packets Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0184"/>
        <description>Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1374"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1373"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1372"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:975" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:974" version="1" class="vulnerability">
      <metadata>
        <title>IE Frame Domain Verification Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0027"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to read certain files and spoof the URL in the address bar by using the Document.open function to pass information between two frames from different domains, a new variant of the "Frame Domain Verification" vulnerability described in MS:MS01-058/CAN-2001-0874.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-20T04:04:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:1451"/>
        <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
        <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:972" version="1" class="vulnerability">
      <metadata>
        <title>tcpdump Delete Payload in ISAKMP Packets Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0183"/>
        <description>TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via ISAKMP packets containing a Delete payload with a large number of SPI's, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1374"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1373"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1372"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1371"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:971" version="1" class="vulnerability">
      <metadata>
        <title>libpng Malformed PNG Image Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0421" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0421"/>
        <description>The Portable Network Graphics library (libpng) 1.0.15 and earlier allows attackers to cause a denial of service (crash) via a malformed PNG image file that triggers an error that causes an out-of-bounds read when creating the error message.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="libpng/libpng-devel is less than 1.2.2-21 or libpng10/libpng-devel less than 1.0.13 is installed">
          <criterion comment="libpng version is less than 1.2.2-21" negate="false" test_ref="oval:org.mitre.oval:tst:1378"/>
          <criterion comment="libpng-devel version is less than 1.2.2-21" negate="false" test_ref="oval:org.mitre.oval:tst:1377"/>
          <criterion comment="libpng10 version is less than 1.0.13-12" negate="false" test_ref="oval:org.mitre.oval:tst:1376"/>
          <criterion comment="libpng10-devel version is less than 1.0.13-12" negate="false" test_ref="oval:org.mitre.oval:tst:1375"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:970" version="1" class="vulnerability">
      <metadata>
        <title>CVS pserver BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0396"/>
        <description>Heap-based buffer overflow in CVS 1.11.x up to 1.11.15, and 1.12.x up to 1.12.7, when using the pserver mechanism allows remote attackers to execute arbitrary code via Entry lines.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-22" negate="false" test_ref="oval:org.mitre.oval:tst:1382"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:97" version="1" class="vulnerability">
      <metadata>
        <title>Solaris cachefsd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0084"/>
        <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Updated to add patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Added Solaris 9 and Solaris 9 patch test to the definition">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 110896-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2946"/>
          <criterion comment="Patch 114008-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3050"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:969" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807"/>
        <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-18T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-02T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:02.359-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows NT 4.0 Server or Terminal Server is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criteria operator="OR" comment="Server or Terminal Server product option">
              <criteria operator="OR" comment="Windows NT server product option">
                <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
                <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
              </criteria>
              <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of rpcproxy.dll exists on NT">
            <criteria operator="AND" comment="non Terminal Server and rpcproxy.dll is less than 4.0.1381.7255">
              <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of rpcproxy.dll is less than 4.0.1381.7255" negate="false" test_ref="oval:org.mitre.oval:tst:1385"/>
            </criteria>
            <criteria operator="AND" comment="Terminal Server and rpcproxy.dll is less than 4.0.1381.33559">
              <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of rpcproxy.dll is less than 4.0.1381.33559" negate="false" test_ref="oval:org.mitre.oval:tst:1384"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="COM Internet Services are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:968" version="1" class="vulnerability">
      <metadata>
        <title>MS Jet Database Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Jet Database Engine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0197" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0197"/>
        <description>Buffer overflow in Microsoft Jet Database Engine 4.0 allows remote attackers to execute arbitrary code via a specially-crafted database query.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="a vulnerable version of Microsoft Jet 4.0 is installed">
          <criteria operator="AND" comment="32-bit version of Windows and msjet40.dll is less than 4.0.8618.0">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the version of msjet40.dll is less than 4.0.8618.0" negate="false" test_ref="oval:org.mitre.oval:tst:1388"/>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and wmsjet40.dll is less than 4.0.8618.0">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of wmsjet40.dll is less than 4.0.8618.0" negate="false" test_ref="oval:org.mitre.oval:tst:1387"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb837001 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:967" version="1" class="vulnerability">
      <metadata>
        <title>rsync Path Sanitation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0426" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0426"/>
        <description>rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot, which allows remote attackers to write files outside of the module's path.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="rsync version is less than 2.5.7-4.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:966" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Media Services ISAPI Logging Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0227"/>
        <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" negate="false" test_ref="oval:org.mitre.oval:tst:1390"/>
        <criterion comment="Patch KB817772 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1439"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:965" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Script Execution Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1190"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:964" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of h323.tsp exists">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of h323.tsp exists">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of h323.tsp exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and h323.tsp is less than 5.1.2600.134">
                <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                <criterion comment="the version of h323.tsp is less than 5.1.2600.134" negate="false" test_ref="oval:org.mitre.oval:tst:1392"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and h323.tsp is less than 5.1.2600.1348">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of h323.tsp is less than 5.1.2600.1348" negate="false" test_ref="oval:org.mitre.oval:tst:1391"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and h323.tsp is less than 5.1.2600.1348">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of h323.tsp is less than 5.1.2600.1348" negate="false" test_ref="oval:org.mitre.oval:tst:1391"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:963" version="1" class="vulnerability">
      <metadata>
        <title>IE File Upload Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0114" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0114"/>
        <description>The file upload control in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to automatically upload files from the local system via a web page containing a script to upload the files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:962" version="1" class="vulnerability">
      <metadata>
        <title>MDAC SQL-DMO Buffer Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Components 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="DataAccess Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1394"/>
        <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" negate="false" test_ref="oval:org.mitre.oval:tst:1393"/>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:961" version="1" class="vulnerability">
      <metadata>
        <title>MDAC SQL-DMO Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="split out the MDAC and file version tests from the compound test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" negate="false" test_ref="oval:org.mitre.oval:tst:1396"/>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:960" version="1" class="vulnerability">
      <metadata>
        <title>Magick XWD Decoder DoS</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1739"/>
        <description>The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ImageMagick RPM earlier than 0:5.5.6-15" negate="false" test_ref="oval:org.mitre.oval:tst:1397"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:96" version="1" class="vulnerability">
      <metadata>
        <title>IE Cookie-based Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0078"/>
        <description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2715.400" negate="false" test_ref="oval:org.mitre.oval:tst:2952"/>
          <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="cookies are enabled">
            <criteria operator="AND" comment="current user settings are being used and cookies are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="persistent cookies that are stored on your computer are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2950"/>
              <criterion comment="persistent cookies that are stored on your computer are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2949"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and cookies are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="per-session cookies (not stored) are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2948"/>
              <criterion comment="per-session cookies (not stored) are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2947"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:959" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 WMF/EMF Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Enhanced Metafile (EMF)</product>
          <product>Windows Metafile (WMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0906"/>
        <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of mf3216.dll is less than 5.0.2195.6898" negate="false" test_ref="oval:org.mitre.oval:tst:1398"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:958" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:22:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists on XP">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of rpcss.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of rpcss.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and rpcss.dll is less than 5.1.2600.135">
                  <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                  <criterion comment="the version of rpcss.dll is less than 5.1.2600.135" negate="false" test_ref="oval:org.mitre.oval:tst:1400"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and rpcss.dll is less than 5.1.2600.1361">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of rpcss.dll is less than 5.1.2600.1361" negate="false" test_ref="oval:org.mitre.oval:tst:1399"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and rpcss.dll is less than 5.1.2600.1361">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of rpcss.dll is less than 5.1.2600.1361" negate="false" test_ref="oval:org.mitre.oval:tst:1399"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:956" version="1" class="vulnerability">
      <metadata>
        <title>IE .chm Directory Traversal Windows NT Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1041"/>
        <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
            <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
            <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          </criteria>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:955" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS Service DCOM Activation Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0116" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0116"/>
        <description>An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.6906" negate="false" test_ref="oval:org.mitre.oval:tst:1407"/>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:954" version="1" class="vulnerability">
      <metadata>
        <title>Konqueror URI Handler "-" Filter Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0411" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0411"/>
        <description>The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1.3-6.4" negate="false" test_ref="oval:org.mitre.oval:tst:1426"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="telnet, rlogin, ssh or kmail is executable">
            <criteria operator="OR" comment="/usr/bin/telnet is executable">
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1425"/>
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1424"/>
              <criterion comment="/usr/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1423"/>
            </criteria>
            <criteria operator="OR" comment="/usr/kerberos/bin/telnet is executable">
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1422"/>
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1421"/>
              <criterion comment="/usr/kerberos/bin/telnet is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1420"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rlogin is executable">
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1419"/>
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1418"/>
              <criterion comment="/usr/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1417"/>
            </criteria>
            <criteria operator="OR" comment="/usr/kerberos/bin/rlogin is executable">
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1416"/>
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1415"/>
              <criterion comment="/usr/kerberos/bin/rlogin is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1414"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ssh is executable">
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1413"/>
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1412"/>
              <criterion comment="/usr/bin/ssh is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1411"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/kmail is executable">
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1410"/>
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1409"/>
              <criterion comment="/usr/bin/kmail is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1408"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:952" version="1" class="vulnerability">
      <metadata>
        <title>NT4.0 SNMP Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>SNMP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0815"/>
        <description>Memory leak in SNMP agent in Windows NT 4.0 before SP5 allows remote attackers to conduct a denial of service (memory exhaustion) via a large number of queries.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-14T12:00:00.000-04:00" comment="Switched the service pack test from wrt-373 to wrt-539.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" negate="false" test_ref="oval:org.mitre.oval:tst:1427"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:951" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false" test_ref="oval:org.mitre.oval:tst:1501"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion comment="PCT support is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:950" version="2">
      <metadata>
        <title>Microsoft Excel Malformed OBJECT record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1306" source="CVE"/>
        <description>Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted BIFF record with an attacker-controlled array index that is used for a function pointer, aka "Malformed OBJECT record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:40.980-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.316-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:95" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS ASP Server-Side Include Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0149"/>
        <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:948" version="1" class="vulnerability">
      <metadata>
        <title>IE File Download Dialog Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0309"/>
        <description>Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file download dialogs, which eventually cause Internet Explorer to execute the program, as demonstrated using a large number of FRAME or IFRAME tags, aka the "File Download Dialog Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:947" version="1" class="vulnerability">
      <metadata>
        <title>KAME IKE Daemon Improper Hash Value Handling</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0164" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0164"/>
        <description>KAME IKE daemon (racoon) does not properly handle hash values, which allows remote attackers to delete certificates via (1) a certain delete message that is not properly handled in isakmp.c or isakmp_inf.c, or (2) a certain INITIAL-CONTACT message that is not properly handled in isakmp_inf.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:946" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of h323.tsp is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1428"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:945" version="1" class="vulnerability">
      <metadata>
        <title>Racoon IKE Daemon Unauthorized X.509 Certificate Connection Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0155"/>
        <description>The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ipsec-tools version is less than 0.2.5-0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1430"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="racoon is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1429"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:944" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Cross-site Scripting Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1181"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" negate="false" test_ref="oval:org.mitre.oval:tst:1448"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:943" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Xsun</product>
        </affected>
        <reference source="MISC" ref_id="http://sunsolve9.sun.com/search/document.do?assetkey=1-26-101800-1&amp;searchclause="/>
        <description>A security vulnerability in Xsun and Xprt may allow a local unprivileged user to execute arbitrary code at the privilege level of either the XSun or Xprt command.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.666-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.243-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criterion comment="Solaris 7 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 108652-93 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3400"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 108653-82 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3355"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112785-50 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4130"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112786-39 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3404"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 119059-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3997"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101800 criteria." negate="false">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 119060-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3529"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criteria operator="AND" comment="File Xsun is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xsun SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
          <criteria operator="AND" comment="File Xprt is SUID|SGID AND Executable" negate="false">
            <criteria operator="OR" comment="File Xprt SUID|SGID" negate="false">
              <criterion comment="File Xsun SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3963"/>
              <criterion comment="File Xprt SUID" negate="false" test_ref="oval:org.mitre.oval:tst:3558"/>
            </criteria>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3178"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:942" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Cross-site Scripting Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1181" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1181"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the administrative web pages for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allow remote attackers to execute HTML script as other users through (1) a certain ASP file in the IISHELP virtual directory, or (2) possibly other unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:941" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5.STABLE3-5.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1431"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:940" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel ISO9660 File System Component BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0109"/>
        <description>Buffer overflow in the ISO9660 file system component for Linux kernel 2.4.x, 2.5.x and 2.6.x , allows local users with physical access to overflow kernel memory and execute arbitrary code via a malformed CD containing a long symbolic link entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="kernel versions">
            <criterion comment="kernel version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1436"/>
            <criterion comment="kernel-smp version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1435"/>
            <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1434"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/bin/mount is world-executable AND Set-UID">
            <criterion comment="/bin/mount is world-executable AND Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:1433"/>
            <criterion comment="/bin/mount is world-executable AND Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:1432"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:94" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 108869-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3125"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:939" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel ip_setsockopt Integer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0424" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0424"/>
        <description>Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="kernel versions">
          <criterion comment="kernel version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1436"/>
          <criterion comment="kernel-smp version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1435"/>
          <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1434"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:938" version="1" class="vulnerability">
      <metadata>
        <title>IIS5.0 Windows Media Services Large POST Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0349"/>
        <description>Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" negate="false" test_ref="oval:org.mitre.oval:tst:1437"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:937" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:936" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Media Services ISAPI Logging Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0227"/>
        <description>The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (IIS) and execute arbitrary code via a certain network request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" negate="false" test_ref="oval:org.mitre.oval:tst:1440"/>
        <criterion comment="Patch KB817772 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1439"/>
        <criterion comment="Patch KB822343 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:935" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion comment="Patch PHNE_32606 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:933" version="1" class="vulnerability">
      <metadata>
        <title>IIS WebDAV Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0226" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0226"/>
        <description>Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:43:00.000-04:00" comment="modified wft-332 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:1444"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1443"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:932" version="1" class="vulnerability">
      <metadata>
        <title>IIS showcode.asp Sample File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0736"/>
        <description>The showcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\code.asp is less than 4.0.1381.279" negate="false" test_ref="oval:org.mitre.oval:tst:1446"/>
        <criterion comment="Patch Q232449 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1445"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:931" version="1" class="vulnerability">
      <metadata>
        <title>IIS5.0 Script Source Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1180"/>
        <description>A typographical error in the script source access permissions for Internet Information Server (IIS) 5.0 does not properly exclude .COM files, which allows attackers with only write permissions to upload malicious .COM files, aka "Script Source Access Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:930" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:929" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Out of Process Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0869"/>
        <description>Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" negate="false" test_ref="oval:org.mitre.oval:tst:1448"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:928" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL Kerberos Handshake Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112"/>
        <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:927" version="1" class="vulnerability">
      <metadata>
        <title>IIS5.0 Specialized Header Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0778" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0778"/>
        <description>IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:926" version="1" class="vulnerability">
      <metadata>
        <title>IE URLMON Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0113"/>
        <description>Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via an HTTP response containing long values in (1) Content-type and (2) Content-encoding fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" negate="false" test_ref="oval:org.mitre.oval:tst:1449"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:925" version="1" class="vulnerability">
      <metadata>
        <title>MS IE HTML Directive Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0022"/>
        <description>Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be concatenated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:1451"/>
          <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
          <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Run ActiveX Controls and Plugins Not Disabled">
            <criterion comment="Use Machine Settings" negate="false" test_ref="oval:org.mitre.oval:tst:1456"/>
            <criterion comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:1450"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:924" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 ASN.1 Library Double-free Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0123"/>
        <description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of msasn1.dll is less than 5.2.3790.139" negate="false" test_ref="oval:org.mitre.oval:tst:1452"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:923" version="1" class="vulnerability">
      <metadata>
        <title>Zone Spoofing through Malformed Web Page Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0190"/>
        <description>Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:1453"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:922" version="1" class="vulnerability">
      <metadata>
        <title>IE Slash Characters in Type Property Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0344"/>
        <description>Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:921" version="1" class="vulnerability">
      <metadata>
        <title>IE File Execution User-prompt Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0727"/>
        <description>Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "File Execution Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2712.0300" negate="false" test_ref="oval:org.mitre.oval:tst:1460"/>
          <criterion comment="Patch Q313675 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1459"/>
          <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
          <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Downloads Not Disabled">
            <criterion comment="Use Machine Settings" negate="false" test_ref="oval:org.mitre.oval:tst:1456"/>
            <criterion comment="File Downloads Allowed In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:1455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:920" version="1" class="vulnerability">
      <metadata>
        <title>IE Cached Content Command Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0002"/>
        <description>Internet Explorer 5.5 and earlier allows remote attackers to obtain the physical location of cached content and open the content in the Local Computer Zone, then use compiled HTML help (.chm) files to execute arbitrary programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1466"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1465"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1464"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" negate="false" test_ref="oval:org.mitre.oval:tst:1463"/>
        <criterion comment="Patch Q286045 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1462"/>
        <criterion comment="Patch Q295106 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:92" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS HTTP Error Page Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148"/>
        <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:919" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 LSASS Buffer Overflow (Sasser Worm Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of lsasrv.dll is less than 5.2.3790.134" negate="false" test_ref="oval:org.mitre.oval:tst:1467"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:918" version="2">
      <metadata>
        <title>Microsoft Office Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-1316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1316" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with malformed string that triggers memory corruption related to record lengths, aka "Microsoft Office Parsing Vulnerability," a different vulnerability than CVE-2006-2389.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:40.581-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:50.027-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Project 2002, SP1" operator="AND">
          <extend_definition comment="Microsoft Project 2002, SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Visio 2002" operator="AND">
          <extend_definition comment="Microsoft Visio 2002 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
        <criteria comment="Project 2000, SP1" operator="AND">
          <extend_definition comment="Microsoft Project 2000, SP1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Catch-all for the 2000 version of the Mso9.dll library." operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Catchall for the 2002 version of the Mso.dll library." operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Catchall for the 2003 version of the Mso.dll library." operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:917" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:915" version="1" class="vulnerability">
      <metadata>
        <title>IIS4.0 Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0874"/>
        <description>Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .HTR, .IDC, or .STM extensions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" negate="false" test_ref="oval:org.mitre.oval:tst:1470"/>
        <criterion comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1469"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:914" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-3.0.2" negate="false" test_ref="oval:org.mitre.oval:tst:1468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:913" version="1" class="vulnerability">
      <metadata>
        <title>IIS ASP Source Code Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0278" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0278"/>
        <description>In IIS, remote attackers can obtain source code for ASP files by appending "::$DATA" to the URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" negate="false" test_ref="oval:org.mitre.oval:tst:1470"/>
        <criterion comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1469"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:912" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS System File Listing Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0507"/>
        <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-305 - changed the version of msw3prt.dll to test against from 5.5.2195.3649 to 5.0.2195.3649">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" negate="false" test_ref="oval:org.mitre.oval:tst:1471"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:911" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Local Descriptor Table Kernel Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Local Descriptor Table (LDT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0910"/>
        <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of wintrust.dll is less than 5.131.1880.14" negate="false" test_ref="oval:org.mitre.oval:tst:1472"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:910" version="1" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="nwwks.dll is less than 5.2.3790.2506" negate="false" test_ref="oval:org.mitre.oval:tst:1473"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:91" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2969"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:909" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS System File Listing Privilege Elevation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0507" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0507"/>
        <description>IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges via a Trojan horse file, aka the "System file listing privilege elevation" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" negate="false" test_ref="oval:org.mitre.oval:tst:1474"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:907" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 H.323 Protocol Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>H.323</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0117"/>
        <description>Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of h323.tsp is less than 5.0.2195.6901" negate="false" test_ref="oval:org.mitre.oval:tst:1475"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:906" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Agent Security Prompt Spoofing Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
        <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T08:32:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-17T09:54:00.000-04:00" comment="Updated obj:1000 to use new variable var:759 for path reference rather than var:200.  Now uses 'msagent' subdir of SystemRoot instead of System32.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-11-17T09:54:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:01.838-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment=" a vulnerable version of agentdpv exists">
            <criteria operator="AND" comment="a vulnerable version of agentdpv exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of agentdpv.dll is less than 2.0.0.3423" negate="false" test_ref="oval:org.mitre.oval:tst:2425"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1241" negate="false" test_ref="oval:org.mitre.oval:tst:1476"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64)">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1241" negate="false" test_ref="oval:org.mitre.oval:tst:1476"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb890046 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2424"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:905" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:904" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Help Center Command Insertion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0907" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0907"/>
        <description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified date="2004-05-12T12:00:00.000-04:00" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:40.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of helpctr.exe is less than 5.2.3790.125" negate="false" test_ref="oval:org.mitre.oval:tst:1478"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the HCP Protocol is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:903" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="the version of schannel.dll is less than 4.87.1964.1880" negate="false" test_ref="oval:org.mitre.oval:tst:1479"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion comment="PCT support is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:902" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:901" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 COM Structured Storage Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0047"/>
        <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-02-16T12:00:00.000-04:00" comment="Added compound statement to include three platforms">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-02-23T08:48:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of ole32.dll is less than 5.2.3790.250" negate="false" test_ref="oval:org.mitre.oval:tst:1486"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
        <criteria operator="OR" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:900" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP RPCSS DCOM Buffer Overflow (Blaster)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of rpcrt4.dll exists on XP">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of rpcrt4.dll exists">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of rpcrt4.dll exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.135">
                <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.135" negate="false" test_ref="oval:org.mitre.oval:tst:1488"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and rpcrt4.dll is less than 5.1.2600.1361">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1361" negate="false" test_ref="oval:org.mitre.oval:tst:1487"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and rpcrt4.dll is less than 5.1.2600.1361">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1361" negate="false" test_ref="oval:org.mitre.oval:tst:1487"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:90" version="1" class="vulnerability">
      <metadata>
        <title>IIS Denial of Service via WebDAV</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0151"/>
        <description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-10-20T10:07:00.000-04:00" comment="corrected configuration criterion">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" negate="false" test_ref="oval:org.mitre.oval:tst:2955"/>
          <criterion comment="Patch Q291845 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2954"/>
          <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
          <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3019"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="WebDav is disabled(for iis 5.0)" negate="true" test_ref="oval:org.mitre.oval:tst:2953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:9" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 RPC xdr_array Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>libnsl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:40.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criteria operator="OR" comment="rpc.cmsd or dmispd exist">
            <criterion comment="File rpc.cmsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3140"/>
            <criterion comment="File dmispd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3139"/>
          </criteria>
          <criteria operator="AND" comment="Patches 108827-30 and 108901-06" negate="true">
            <criterion comment="Patch 108827-30 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3138"/>
            <criterion comment="Patch 108901-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3137"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="rpc.cmsd enabled OR dmispd running">
            <criteria operator="AND" comment="rpc.cmsd enabled">
              <criterion comment="" negate="false" test_ref="oval:org.mitre.oval:tst:3136"/>
              <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
              <criteria operator="OR" comment="File rpc.cmsd executable">
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3134"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3133"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3132"/>
              </criteria>
            </criteria>
            <criterion comment="dmispd running" negate="false" test_ref="oval:org.mitre.oval:tst:3131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:899" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.417-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.065-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:898" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP LSASS Buffer Overflow (Sasser Worm Vulnerability)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:22:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="a vulnerable version of lsasrv.dll exists on XP">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of lsasrv.dll exists">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of lsasrv.dll exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and lsasrv.dll is less than 5.1.2600.134">
                <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                <criterion comment="the version of lsasrv.dll is less than 5.1.2600.134" negate="false" test_ref="oval:org.mitre.oval:tst:1490"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and lsasrv.dll is less than 5.1.2600.1361">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of lsasrv.dll is less than 5.1.2600.1361" negate="false" test_ref="oval:org.mitre.oval:tst:1489"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and lsasrv.dll is less than 5.1.2600.1361">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of lsasrv.dll is less than 5.1.2600.1361" negate="false" test_ref="oval:org.mitre.oval:tst:1489"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:897" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT WMF/EMF Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Enhanced Metafile (EMF)</product>
          <product>Windows Metafile (WMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0906"/>
        <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criteria operator="OR" comment="a vulnerable version of mf3216.dll exists on NT">
          <criteria operator="AND" comment="non Terminal Server and mf3216.dll is less than 4.0.1381.7263">
            <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of mf3216.dll is less than 4.0.1381.7263" negate="false" test_ref="oval:org.mitre.oval:tst:1492"/>
          </criteria>
          <criteria operator="AND" comment="NT Terminal Server and mf3216.dll is less than 4.0.1381.33562">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of mf3216.dll is less than 4.0.1381.33562" negate="false" test_ref="oval:org.mitre.oval:tst:1491"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:896" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 winlogon Remote Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows logon process (winlogon)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0806"/>
        <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:54:00.000-04:00" comment="modified wft-133 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-23T19:48:00.000-04:00" comment="fixed  tst:1493 by changing referrence to obj:862 (msgina.dll) instead of obj:958 (msjet40.dll).">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-09-23T20:21:00.000-04:00" comment="Replaced use of  tst:3085 to test for Windows 2000 with extended inventory definition def:85.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-23T21:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-10T20:40:01.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <extend_definition comment="Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the version of msgina.dll is less than 5.0.2195.6895" negate="false" test_ref="oval:org.mitre.oval:tst:1493"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="machine is a member of a domain" negate="false" test_ref="oval:org.mitre.oval:tst:1494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:895" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT winlogon Remote Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows logon process (winlogon)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0806"/>
        <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="a vulnerable version of msgina.dll exists on NT">
            <criteria operator="AND" comment="non Terminal Server and msgina.dll is less than 4.0.1381.7255">
              <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of msgina.dll is less than 4.0.1381.7255" negate="false" test_ref="oval:org.mitre.oval:tst:1496"/>
            </criteria>
            <criteria operator="AND" comment="Terminal Server and msgina.dll is less than 4.0.1381.33559">
              <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
              <criterion comment="the version of msgina.dll is less than 4.0.1381.33559" negate="false" test_ref="oval:org.mitre.oval:tst:1495"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="machine is a member of a domain" negate="false" test_ref="oval:org.mitre.oval:tst:1494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:893" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0813"/>
        <description>A multi-threaded race condition in the Windows RPC DCOM functionality with the MS03-039 patch installed allows remote attackers to cause a denial of service (crash or reboot) by causing two threads to process the same RPC request, which causes one thread to use memory after it has been freed, a different vulnerability than CVE-2003-0352 (Blaster/Nachi), CVE-2003-0715, and CVE-2003-0528, and as demonstrated by certain exploits against those vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6904" negate="false" test_ref="oval:org.mitre.oval:tst:1500"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:892" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of schannel.dll is less than 5.1.2195.6899" negate="false" test_ref="oval:org.mitre.oval:tst:1501"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:891" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:890" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Local Descriptor Table Kernel Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Descriptor Table (LDT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0910" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0910"/>
        <description>The NtSetLdtEntries function in the programming interface for the Local Descriptor Table (LDT) in Windows NT 4.0 and Windows 2000 allows local attackers to gain access to kernel memory and execute arbitrary code via an expand-down data segment descriptor descriptor that points to protected memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of wintrust.dll is less than 5.131.2195.6824" negate="false" test_ref="oval:org.mitre.oval:tst:1502"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:89" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 MUP UNC Request Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Multiple UNC Provider (MUP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0151"/>
        <description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" negate="false" test_ref="oval:org.mitre.oval:tst:2957"/>
        <criterion comment="Patch Q311967 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2956"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:889" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:21:00.000-04:00" comment="added cmp-66">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of schannel.dll exists">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of schannel.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136">
                  <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.136" negate="false" test_ref="oval:org.mitre.oval:tst:1507"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" negate="false" test_ref="oval:org.mitre.oval:tst:1506"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" negate="false" test_ref="oval:org.mitre.oval:tst:1506"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion comment="PCT support is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:888" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:887" version="1" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Enterprise 3 Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1505"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1504"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:886" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:29:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of schannel.dll exists">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of schannel.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of schannel.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and schannel.dll is less than 5.1.2600.136">
                  <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.136" negate="false" test_ref="oval:org.mitre.oval:tst:1507"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and schannel.dll is less than 5.1.2600.1347">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" negate="false" test_ref="oval:org.mitre.oval:tst:1506"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and schannel.dll is less than 5.1.2600.1347">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of schannel.dll is less than 5.1.2600.1347" negate="false" test_ref="oval:org.mitre.oval:tst:1506"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:885" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 SSL Library Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Secure Sockets Layer (SSL)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0120"/>
        <description>The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1509"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:883" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 LSASS Buffer Overflow (Sasser Worm Vulnerability)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0533" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0533"/>
        <description>Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via a packet that causes the DsRolerUpgradeDownlevelServer function to create long debug entries for the DCPROMO.LOG log file, as exploited by the Sasser worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:1511"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:882" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v5.5,SP2 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4939.300" negate="false" test_ref="oval:org.mitre.oval:tst:1513"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:881" version="1" class="vulnerability">
      <metadata>
        <title>Bourne Shell Local-DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1780" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1780"/>
        <description>The Bourne shell (sh) in Solaris 8, 9, and 10 allows local users to cause a denial of service (sh crash) via an unspecified attack vector that causes sh processes to crash during creation of temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109324-09 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1520"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118535-03 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1519"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121004-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1518"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109325-09 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1517"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118536-03 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1516"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102282 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121005-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1515"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:880" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via 0-Length Presentation Protocol Selector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0367"/>
        <description>Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a zero-length Presentation protocol selector.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:88" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal SPNEGO Dissoector Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0430" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0430"/>
        <description>The SPNEGO dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (crash) via an invalid ASN.1 value.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:879" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Ethereal Denial of Service via Malformed RADIUS Packet</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0365" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0365"/>
        <description>The dissect_attribute_value_pairs function in packet-radius.c for Ethereal 0.8.13 to 0.10.2 allows remote attackers to cause a denial of service (crash) via a malformed RADIUS packet that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:878" version="1" class="vulnerability">
      <metadata>
        <title>Multiple BO Vulnerabilities in Red Hat Ethereal</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0176"/>
        <description>Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) NetFlow, (2) IGAP, (3) EIGRP, (4) PGM, (5) IrDA, (6) BGP, (7) ISUP, or (8) TCAP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1531"/>
            <criterion comment="ethereal-gnome version is less than 0.10.3-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1530"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1529"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1528"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1527"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1526"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1525"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1524"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tethereal is executable">
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1523"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1522"/>
              <criterion comment="/usr/bin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1521"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:877" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Squid ACL Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Red Hat 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0189"/>
        <description>The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-07T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="squid version is less than 2.5STABLE1-3.9" negate="false" test_ref="oval:org.mitre.oval:tst:1533"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="squid is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:876" version="1" class="vulnerability">
      <metadata>
        <title>Apache 2 Denial of Service due to Memory Leak in mod_ssl</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0113" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0113"/>
        <description>Memory leak in ssl_engine_io.c for mod_ssl in Apache 2 before 2.0.49 allows remote attackers to cause a denial of service (memory consumption) via plain HTTP requests to the SSL port of an SSL-enabled server.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_ssl version is less than 2.0.46-32.ent" negate="false" test_ref="oval:org.mitre.oval:tst:1534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:875" version="1" class="vulnerability">
      <metadata>
        <title>XMLSoft Libxml2 Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110"/>
        <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-22T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="libxml2 version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1609"/>
          <criterion comment="libxml2-devel version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1608"/>
          <criterion comment="libxml2-python version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:874" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Zombie Document Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0191"/>
        <description>Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:873" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Mozilla Bypass Cookie Access Restrictions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0594"/>
        <description>Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Mozilla to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mozilla version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1538"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mozilla is executable">
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1537"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1536"/>
            <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1535"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:872" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat S/MIME Protocol Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0564"/>
        <description>Multiple vulnerabilities in multiple vendor implementations of the Secure/Multipurpose Internet Mail Extensions (S/MIME) protocol allow remote attackers to cause a denial of service and possibly execute arbitrary code via an S/MIME email message containing certain unexpected ASN.1 constructs, as demonstrated using the NISSC test suite.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="mozilla-nss version is less than 1.4.2-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1539"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:871" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL Improper Unknown Message Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0081"/>
        <description>OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:870" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 OpenSSL do_change_cipher_spec Function Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1543"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1542"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-33.4" negate="false" test_ref="oval:org.mitre.oval:tst:1541"/>
        <criterion comment="openssl096b version is less than 0.9.6b-16" negate="false" test_ref="oval:org.mitre.oval:tst:1540"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:87" version="1" class="vulnerability">
      <metadata>
        <title>SNMPv1 Request Handling DoS and Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0013"/>
        <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of snmp.exe is less than 4.0.1381.7134" negate="false" test_ref="oval:org.mitre.oval:tst:2960"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:869" version="1" class="vulnerability">
      <metadata>
        <title>Net-SNMP MIB Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Net-SNMP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0935" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0935"/>
        <description>Net-SNMP before 5.0.9 allows a user or community to access data in MIB objects, even if that data is not allowed to be viewed.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="net-snmp version is less than 5.0.9-2.30E.1" negate="false" test_ref="oval:org.mitre.oval:tst:1545"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1544"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:868" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel eflags Checking Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0001"/>
        <description>Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:1547"/>
        <criterion comment="kernel version is less than 2.4.21-9.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1546"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:867" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1550"/>
          <criterion comment="kernel-smp version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1549"/>
          <criterion comment="kernel-bigmem version is less than 2.4.21-4.0.2.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1548"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:866" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-14" negate="false" test_ref="oval:org.mitre.oval:tst:1551"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:865" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1.3-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1552"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:864" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.46-26.ent" negate="false" test_ref="oval:org.mitre.oval:tst:1553"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:863" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Multiple stack-based BO Vulnerabilities in Apache</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>httpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.9" negate="false" test_ref="oval:org.mitre.oval:tst:1554"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:862" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.EL3.2" negate="false" test_ref="oval:org.mitre.oval:tst:1555"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:861" version="1" class="vulnerability">
      <metadata>
        <title>rpc.mountd Denial of Service via NFS Mount</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>nfs-utils packages</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0154"/>
        <description>rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="nfs-utils version is less than 1.0.6-7.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1557"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.mountd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1556"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:860" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Denial of Service Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0985"/>
        <description>The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:86" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 LBXProxy Display Name Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>lbxproxy</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0090"/>
        <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File lbxproxy exists" negate="false" test_ref="oval:org.mitre.oval:tst:2964"/>
          <criterion comment="Patch 108652-51 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2963"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File lbxproxy SGID and executable">
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2962"/>
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:859" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel Real Time Clock Data Leakage</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0984"/>
        <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1560"/>
          <criterion comment="kernel-smp version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1559"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-28.9" negate="false" test_ref="oval:org.mitre.oval:tst:1558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:858" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat kdepim VCF File Information Reader BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE Personal Information Management (kdepim)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0988"/>
        <description>Buffer overflow in the VCF file information reader for KDE Personal Information Management (kdepim) suite in KDE 3.1.0 through 3.1.4 allows attackers to execute arbitrary code via a VCF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdepim version is less than 3.1-6" negate="false" test_ref="oval:org.mitre.oval:tst:1564"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/share/services/kfile_vcf.desktop is readable">
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1563"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1562"/>
            <criterion comment="/usr/share/services/kfile_vcf.desktop is readable" negate="false" test_ref="oval:org.mitre.oval:tst:1561"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:857" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed Q.931 Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Tethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1013"/>
        <description>The Q.931 dissector in Ethereal before 0.10.0, and Tethereal, allows remote attackers to cause a denial of service (crash) via a malformed Q.931, which triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:856" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal Malformed SMB Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1012"/>
        <description>The SMB dissector in Ethereal before 0.10.0 allows remote attackers to cause a denial of service via a malformed SMB packet that triggers a segmentation fault during processing of Selected packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="ethereal version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1575"/>
            <criterion comment="ethereal-gnome version is less than 0.10.0a-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:1574"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/ethereal is executable">
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1573"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1572"/>
              <criterion comment="/usr/bin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1571"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/ethereal is executable">
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1570"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1569"/>
              <criterion comment="/usr/sbin/ethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1568"/>
            </criteria>
            <criteria operator="OR" comment="/usr/sbin/tethereal is executable">
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1567"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1566"/>
              <criterion comment="/usr/sbin/tethereal is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1565"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:855" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat CVS Server root Directory Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CVS server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0977" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0977"/>
        <description>CVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed module requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-13" negate="false" test_ref="oval:org.mitre.oval:tst:1577"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/ is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:1576"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:854" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 tcpdump DoS via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:853" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:852" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 tcpdump DoS via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.E3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:851" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0057"/>
        <description>The rawprint function in the ISAKMP decoding routines (print-isakmp.c) for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via malformed ISAKMP packets that cause invalid "len" or "loc" values to be used in a loop, a different vulnerability than CVE-2003-0989.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:850" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via print_attr_string Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0055"/>
        <description>The print_attr_string function in print-radius.c for tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (segmentation fault) via a RADIUS attribute with a large length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:849" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat sysstat port and trigger Scripts symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>sysstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0107" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0107"/>
        <description>The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="sysstat version is less than 4.0.7-4.rhl9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1579"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:848" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (64-bit WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="cdosys.dll is less than 6.5.6756.0" negate="false" test_ref="oval:org.mitre.oval:tst:2537"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:847" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat tcpdump Denial of Service via ISAKMP Packets</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>tcpdump</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0989"/>
        <description>tcpdump before 3.8.1 allows remote attackers to cause a denial of service (infinite loop) via certain ISAKMP packets, a different vulnerability than CVE-2004-0057.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="tcpdump version is less than 3.7.2-7.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:1583"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/sbin/tcpdump is executable">
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1582"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1581"/>
            <criterion comment="/usr/sbin/tcpdump is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1580"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:846" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1586"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1585"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" negate="false" test_ref="oval:org.mitre.oval:tst:1584"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:845" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 gdk-pixbuf Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gdk-pixbuf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0111"/>
        <description>gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable configuration">
          <criterion comment="gdk-pixbuf version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1589"/>
          <criterion comment="gdk-pixbuf-devel version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1588"/>
          <criterion comment="gdk-pixbuf-gnome version is less than 0.22.0-6.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:1587"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:844" version="1" class="vulnerability">
      <metadata>
        <title>MSN Messenger Remote File Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0122"/>
        <description>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-03-30T12:00:00.000-04:00" comment="Fixed the path for both versions of the file to look at the correct registry key to determine the location of the 'Program Files' folder..">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed">
          <criterion comment="the version of msgsc.dll is greater than 6.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:1591"/>
          <criterion comment="the version of msgsc.dll is less than 6.1.0.211" negate="false" test_ref="oval:org.mitre.oval:tst:1590"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:843" version="1" class="vulnerability">
      <metadata>
        <title>MS Outlook Argument Injection Local Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0121"/>
        <description>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-130 - Added path to the end of the registry key specified in the first component of the file path">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:57:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1595"/>
        <criterion comment="the version of outlook.exe is less than 10.00.5709.0000" negate="false" test_ref="oval:org.mitre.oval:tst:1594"/>
        <criterion comment="the patch kb828040 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1593"/>
        <criterion comment="Microsoft Office XP Service Pack 3 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1592"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:841" version="2">
      <metadata>
        <title>Unhandled Exception Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3648" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 and 2003 SP1, allows remote attackers to execute arbitrary code via unspecified vectors involving unhandled exceptions, memory resident applications, and incorrectly "unloading chained exception."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:39.810-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.708-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Kernel32.dll is less than 5.0.2195.7099" test_ref="oval:org.mitre.oval:tst:80"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Kernel32.dll is less than 5.1.2600.1869" test_ref="oval:org.mitre.oval:tst:31"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Kernel32.dll is less than 5.1.2600.2945" test_ref="oval:org.mitre.oval:tst:45"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.2741" test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.556" test_ref="oval:org.mitre.oval:tst:63"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.2741" test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:840" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:84" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in OSI Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0429" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0429"/>
        <description>The OSI dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via invalid IPv4 or IPv6 prefix lengths, possibly triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:839" version="1" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:838" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.4" negate="false" test_ref="oval:org.mitre.oval:tst:1603"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:837" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:836" version="1" class="vulnerability">
      <metadata>
        <title>Vicam USB Driver Data Copy Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Vicam USB driver</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0075"/>
        <description>The Vicam USB driver in Linux before 2.4.25 does not use the copy_from_user function when copying data from userspace to kernel space, which crosses security boundaries and allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:835" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel ncp_lookup Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010"/>
        <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:834" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Kernel R128 DRI Limits Checking Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003"/>
        <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Configuration">
          <criterion comment="kernel version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1606"/>
          <criterion comment="kernel-smp version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1605"/>
          <criterion comment="kernel-bigmem version is less than 2.4.20-30.9" negate="false" test_ref="oval:org.mitre.oval:tst:1604"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:833" version="1" class="vulnerability">
      <metadata>
        <title>XMLSoft Libxml2 Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XMLSoft Libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0110"/>
        <description>Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="libxml2 version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1609"/>
          <criterion comment="libxml2-devel version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1608"/>
          <criterion comment="libxml2-python version is less than 2.5.10-6" negate="false" test_ref="oval:org.mitre.oval:tst:1607"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:832" version="1" class="vulnerability">
      <metadata>
        <title>XFree86 Improper Handling of Font Files</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:831" version="1" class="vulnerability">
      <metadata>
        <title>XFree86 Buffer Overflow in CopyISOLatin1Lowered Function</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:830" version="1" class="vulnerability">
      <metadata>
        <title>XFree86 Buffer Overflow in dirfile</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Corrected pattern used in rrt-206">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-55.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1610"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:83" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft SQL Server 3-Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MicrosoftSQL Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0542"/>
        <description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf.  NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CVE-2001-0879.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-227 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:57:00.000-04:00" comment="modified wft-227 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File sqlservr.exe version3 less than 2000.80.428.0" negate="false" test_ref="oval:org.mitre.oval:tst:2965"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:828" version="1" class="vulnerability">
      <metadata>
        <title>mod_python Web Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>mod_python</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0973" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0973"/>
        <description>Unknown vulnerability in mod_python 3.0.x before 3.0.4, and 2.7.x before 2.7.9, allows remote attackers to cause a denial of service (httpd crash) via a certain query string.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mod_python version is less than 3.0.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:1612"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:1611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:827" version="1" class="vulnerability">
      <metadata>
        <title>Samba mksmboasswd Disabled Account Creation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Samba 3.0.0 and 3.0.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0082"/>
        <description>The mksmbpasswd shell script (mksmbpasswd.sh) in Samba 3.0.0 and 3.0.1, when creating an account but marking it as disabled, may overwrite the user password with an uninitialized buffer, which could enable the account with a more easily guessable password.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 3.0.2-6.3E" negate="false" test_ref="oval:org.mitre.oval:tst:1613"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:826" version="1" class="vulnerability">
      <metadata>
        <title>RedHat Enterprise 3 Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-7.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1614"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:825" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Linux Kernel do_mremap Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mremap</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0077" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0077"/>
        <description>The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="kernel version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1617"/>
          <criterion comment="kernel-smp version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1616"/>
          <criterion comment="kernel-hugemem version is less than 2.4.21-9.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1615"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:823" version="1" class="vulnerability">
      <metadata>
        <title>Konqueror Cookie Access Restrictions Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0592"/>
        <description>Konqueror in KDE 3.1.3 and earlier (kdelibs) allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal sequences in a URL, which causes Konqueror to send the cookie outside the specified URL subsets, e.g. to a vulnerable application that runs on the same server as the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1-13" negate="false" test_ref="oval:org.mitre.oval:tst:1618"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/konqueror is executable">
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2655"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2654"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:822" version="1" class="vulnerability">
      <metadata>
        <title>Midnight Commander vfs_s_resolve_symlink BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Midnight Commander</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1023"/>
        <description>Stack-based buffer overflow in vfs_s_resolve_symlink of vfs/direntry.c for Midnight Commander (mc) 4.6.0 and earlier, and possibly later versions, allows remote attackers to execute arbitrary code during symlink conversion.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mc version is less than 4.6.0-7.9" negate="false" test_ref="oval:org.mitre.oval:tst:1622"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mc is executable">
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1621"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1620"/>
            <criterion comment="/usr/bin/mc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1619"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:821" version="1" class="vulnerability">
      <metadata>
        <title>slocate Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>slocate</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0848"/>
        <description>Heap-based buffer overflow in main.c of slocate 2.6, and possibly other versions, may allow local users to gain privileges via a modified slocate database that causes a negative "pathlen" value to be used.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="slocate version is less than 2.7-2" negate="false" test_ref="oval:org.mitre.oval:tst:1625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/bin/slocate is setgid">
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1624"/>
            <criterion comment="/usr/bin/slocate is setgid" negate="false" test_ref="oval:org.mitre.oval:tst:1623"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:820" version="1" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic directIM Packet Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0008"/>
        <description>Integer overflow in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:82" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft RPC Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0509"/>
        <description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-04-07T12:00:00.000-04:00" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-04-11T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-12T12:00:00.000-04:00" comment="modified wft-89 - wft-89 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-89 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of ssmsrp70.dll is less than 2000.80.213.0" negate="false" test_ref="oval:org.mitre.oval:tst:2968"/>
        <criterion comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" negate="false" test_ref="oval:org.mitre.oval:tst:2967"/>
        <criterion comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true" test_ref="oval:org.mitre.oval:tst:2966"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:819" version="1" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic Extract Info Field Function BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0007"/>
        <description>Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:818" version="1" class="vulnerability">
      <metadata>
        <title>Gaim / Ultramagnetic BO Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0006"/>
        <description>Multiple buffer overflows in Gaim 0.75 and earlier, and Ultramagnetic before 0.81, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) cookies in a Yahoo web connection, (2) a long name parameter in the Yahoo login web page, (3) a long value parameter in the Yahoo login page, (4) a YMSG packet, (5) the URL parser, and (6) HTTP proxy connect.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gaim version is less than 0.75-0.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:1629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gaim is executable">
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1628"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1627"/>
            <criterion comment="/usr/bin/gaim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1626"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:817" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Shared Object Code Execution</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:816" version="2" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.237-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:815" version="1" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0992" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0992"/>
        <description>Cross-site scripting (XSS) vulnerability in the create CGI script for Mailman before 2.1.3 allows remote attackers to steal cookies of other users.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:813" version="1" class="vulnerability">
      <metadata>
        <title>Mailman Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mailman</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0965" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0965"/>
        <description>Cross-site scripting (XSS) vulnerability in the admin CGI script for Mailman before 2.1.4 allows remote attackers to steal session cookies and conduct unauthorized activities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mailman version is less than 2.1.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:1631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8127" version="1" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing on Double Byte Character Set Systems Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0844"/>
        <description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="true" test_ref="oval:org.mitre.oval:tst:519"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:812" version="2" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (S03-Gold) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:58:00.007-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false" test_ref="oval:org.mitre.oval:tst:1632"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:811" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Mutt BO in Index Menu</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0078" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0078"/>
        <description>Buffer overflow in the index menu code (menu_pad_string of menu.c) for Mutt 1.4.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:810" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1637"/>
            <criterion comment="netpbm-devel version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1636"/>
            <criterion comment="netpbm-progs version is less than 9.24-11.30.1" negate="false" test_ref="oval:org.mitre.oval:tst:1635"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:81" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS HTTP Error Page Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0148"/>
        <description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:809" version="1" class="vulnerability">
      <metadata>
        <title>XFree86 Font File Handling Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0106" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0106"/>
        <description>Multiple unknown vulnerabilities in XFree86 4.1.0 to 4.3.0, related to improper handling of font files, a different set of vulnerabilities than CVE-2004-0083 and CVE-2004-0084.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:808" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 XBL Script Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2261"/>
        <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8077" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0, SP1 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:807" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0084"/>
        <description>Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, allows local or remote authenticated users to execute arbitrary code via a malformed entry in the font alias (font.alias) file, a different vulnerability than CVE-2004-0083 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:806" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat XFree86 Buffer Overflow in ReadFontAlias</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>XFree86</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0083"/>
        <description>Buffer overflow in ReadFontAlias from dirfile.c of XFree86 4.1.0 through 4.3.0 allows local users and remote attackers to execute arbitrary code via a font alias file (font.alias) with a long token, a different vulnerability than CVE-2004-0084 and CVE-2004-0106.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="XFree86 version is less than 4.3.0-2.90.55" negate="false" test_ref="oval:org.mitre.oval:tst:1641"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
            <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1640"/>
            <criteria operator="OR" comment="/usr/X11R6/bin/XFree86 is SUID and executable">
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1639"/>
              <criterion comment="/usr/X11R6/bin/XFree86 is SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:1638"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:805" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:54:00.000-04:00" comment="modified wft-95 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false" test_ref="oval:org.mitre.oval:tst:2572"/>
          <criterion comment="the patch q832894 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2571"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:804" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat netpbm File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>netpbm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0924" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924"/>
        <description>netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="netpbm version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2319"/>
            <criterion comment="netpbm-devel version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2318"/>
            <criterion comment="netpbm-progs version is less than 9.24-10.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2317"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable configuration">
            <criteria operator="OR" comment="/usr/bin/411toppm is executable">
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2316"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2315"/>
              <criterion comment="/usr/bin/411toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2314"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/asciitopgm is executable">
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2313"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2312"/>
              <criterion comment="/usr/bin/asciitopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2311"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/atktopbm is executable">
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2310"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2309"/>
              <criterion comment="/usr/bin/atktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2308"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bioradtopgm is executable">
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2307"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2306"/>
              <criterion comment="/usr/bin/bioradtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2305"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/bmptoppm is executable">
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2304"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2303"/>
              <criterion comment="/usr/bin/bmptoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2302"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/brushtopbm is executable">
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2301"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2300"/>
              <criterion comment="/usr/bin/brushtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2299"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/cmuwmtopbm is executable">
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2298"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2297"/>
              <criterion comment="/usr/bin/cmuwmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2296"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/eyuvtoppm is executable">
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2295"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2294"/>
              <criterion comment="/usr/bin/eyuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2293"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fiascotopnm is executable">
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2292"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2291"/>
              <criterion comment="/usr/bin/fiascotopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2290"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fitstopnm is executable">
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2289"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2288"/>
              <criterion comment="/usr/bin/fitstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2287"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/fstopgm is executable">
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2286"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2285"/>
              <criterion comment="/usr/bin/fstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2284"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/g3topbm is executable">
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2283"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2282"/>
              <criterion comment="/usr/bin/g3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2281"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopbm is executable">
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2280"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2279"/>
              <criterion comment="/usr/bin/gemtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2278"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gemtopnm is executable">
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2277"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2276"/>
              <criterion comment="/usr/bin/gemtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2275"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/giftopnm is executable">
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2274"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2273"/>
              <criterion comment="/usr/bin/giftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2272"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/gouldtoppm is executable">
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2271"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2270"/>
              <criterion comment="/usr/bin/gouldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2269"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hipstopgm is executable">
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2268"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2267"/>
              <criterion comment="/usr/bin/hipstopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2266"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/hpcdtoppm is executable">
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2265"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2264"/>
              <criterion comment="/usr/bin/hpcdtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2263"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/icontopbm is executable">
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2262"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2261"/>
              <criterion comment="/usr/bin/icontopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2260"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ilbmtoppm is executable">
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2259"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2258"/>
              <criterion comment="/usr/bin/ilbmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2257"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/imgtoppm is executable">
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2256"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2255"/>
              <criterion comment="/usr/bin/imgtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2254"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/jpegtopnm is executable">
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2253"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2252"/>
              <criterion comment="/usr/bin/jpegtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2251"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/leaftoppm is executable">
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2250"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2249"/>
              <criterion comment="/usr/bin/leaftoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2248"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/lispmtopgm is executable">
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2247"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2246"/>
              <criterion comment="/usr/bin/lispmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2245"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/macptopbm is executable">
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2244"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2243"/>
              <criterion comment="/usr/bin/macptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2242"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mdatopbm is executable">
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2241"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2240"/>
              <criterion comment="/usr/bin/mdatopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2239"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mgrtopbm is executable">
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2238"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2237"/>
              <criterion comment="/usr/bin/mgrtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2236"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/mtvtoppm is executable">
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2235"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2234"/>
              <criterion comment="/usr/bin/mtvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2233"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/neotoppm is executable">
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2232"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2231"/>
              <criterion comment="/usr/bin/neotoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2230"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/palmtopnm is executable">
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2229"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2228"/>
              <criterion comment="/usr/bin/palmtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2227"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamchannel is executable">
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2226"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2225"/>
              <criterion comment="/usr/bin/pamchannel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2224"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamcut is executable">
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2223"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2222"/>
              <criterion comment="/usr/bin/pamcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2221"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamdeinterlace is executable">
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2220"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2219"/>
              <criterion comment="/usr/bin/pamdeinterlace is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2218"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamfile is executable">
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2217"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2216"/>
              <criterion comment="/usr/bin/pamfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2215"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamoil is executable">
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2214"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2213"/>
              <criterion comment="/usr/bin/pamoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2212"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamstretch is executable">
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2211"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2210"/>
              <criterion comment="/usr/bin/pamstretch is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2209"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pamtopnm is executable">
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2208"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2207"/>
              <criterion comment="/usr/bin/pamtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2206"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmclean is executable">
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2205"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2204"/>
              <criterion comment="/usr/bin/pbmclean is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2203"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmlife is executable">
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2202"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2201"/>
              <criterion comment="/usr/bin/pbmlife is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2200"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmake is executable">
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2199"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2198"/>
              <criterion comment="/usr/bin/pbmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2197"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmmask is executable">
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2196"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2195"/>
              <criterion comment="/usr/bin/pbmmask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2194"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpage is executable">
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2193"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2192"/>
              <criterion comment="/usr/bin/pbmpage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2191"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmpscale is executable">
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2190"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2189"/>
              <criterion comment="/usr/bin/pbmpscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2188"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmreduce is executable">
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2187"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2186"/>
              <criterion comment="/usr/bin/pbmreduce is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2185"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtext is executable">
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2184"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2183"/>
              <criterion comment="/usr/bin/pbmtext is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2182"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto10x is executable">
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2181"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2180"/>
              <criterion comment="/usr/bin/pbmto10x is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2179"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmto4425 is executable">
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2178"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2177"/>
              <criterion comment="/usr/bin/pbmto4425 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2176"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoascii is executable">
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2175"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2174"/>
              <criterion comment="/usr/bin/pbmtoascii is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2173"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoatk is executable">
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2172"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2171"/>
              <criterion comment="/usr/bin/pbmtoatk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2170"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtobbnbg is executable">
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2169"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2168"/>
              <criterion comment="/usr/bin/pbmtobbnbg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2167"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtocmuwm is executable">
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2166"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2165"/>
              <criterion comment="/usr/bin/pbmtocmuwm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2164"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepsi is executable">
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2163"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2162"/>
              <criterion comment="/usr/bin/pbmtoepsi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2161"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoepson is executable">
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2160"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2159"/>
              <criterion comment="/usr/bin/pbmtoepson is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2158"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtog3 is executable">
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2157"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2156"/>
              <criterion comment="/usr/bin/pbmtog3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2155"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogem is executable">
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2154"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2153"/>
              <criterion comment="/usr/bin/pbmtogem is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2152"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtogo is executable">
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2151"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2150"/>
              <criterion comment="/usr/bin/pbmtogo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2149"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoicon is executable">
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2148"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2147"/>
              <criterion comment="/usr/bin/pbmtoicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2146"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolj is executable">
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2145"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2144"/>
              <criterion comment="/usr/bin/pbmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2143"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoln03 is executable">
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2142"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2141"/>
              <criterion comment="/usr/bin/pbmtoln03 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2140"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtolps is executable">
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2139"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2138"/>
              <criterion comment="/usr/bin/pbmtolps is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2137"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomacp is executable">
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2136"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2135"/>
              <criterion comment="/usr/bin/pbmtomacp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2134"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomda is executable">
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2133"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2132"/>
              <criterion comment="/usr/bin/pbmtomda is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2131"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtomgr is executable">
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2130"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2129"/>
              <criterion comment="/usr/bin/pbmtomgr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2128"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtonokia is executable">
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2127"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2126"/>
              <criterion comment="/usr/bin/pbmtonokia is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2125"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopgm is executable">
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2124"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2123"/>
              <criterion comment="/usr/bin/pbmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2122"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopi3 is executable">
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2121"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2120"/>
              <criterion comment="/usr/bin/pbmtopi3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2119"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopk is executable">
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2118"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2117"/>
              <criterion comment="/usr/bin/pbmtopk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2116"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoplot is executable">
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2115"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2114"/>
              <criterion comment="/usr/bin/pbmtoplot is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2113"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoppa is executable">
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2112"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2111"/>
              <criterion comment="/usr/bin/pbmtoppa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2110"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtopsg3 is executable">
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2109"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2108"/>
              <criterion comment="/usr/bin/pbmtopsg3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2107"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoptx is executable">
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2106"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2105"/>
              <criterion comment="/usr/bin/pbmtoptx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2104"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtowbmp is executable">
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2103"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2102"/>
              <criterion comment="/usr/bin/pbmtowbmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2101"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtox10bm is executable">
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2100"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2099"/>
              <criterion comment="/usr/bin/pbmtox10bm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2098"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoxbm is executable">
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2097"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2096"/>
              <criterion comment="/usr/bin/pbmtoxbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2095"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtoybm is executable">
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2094"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2093"/>
              <criterion comment="/usr/bin/pbmtoybm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2092"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmtozinc is executable">
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2091"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2090"/>
              <criterion comment="/usr/bin/pbmtozinc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2089"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pbmupc is executable">
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2088"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2087"/>
              <criterion comment="/usr/bin/pbmupc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2086"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pcxtoppm is executable">
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2085"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2084"/>
              <criterion comment="/usr/bin/pcxtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2083"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmbentley is executable">
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2082"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2081"/>
              <criterion comment="/usr/bin/pgmbentley is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2080"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmcrater is executable">
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2079"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2078"/>
              <criterion comment="/usr/bin/pgmcrater is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2077"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmedge is executable">
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2076"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2075"/>
              <criterion comment="/usr/bin/pgmedge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2074"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmenhance is executable">
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2073"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2072"/>
              <criterion comment="/usr/bin/pgmenhance is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2071"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmhist is executable">
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2070"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2069"/>
              <criterion comment="/usr/bin/pgmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2068"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmkernel is executable">
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2067"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2066"/>
              <criterion comment="/usr/bin/pgmkernel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2065"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnoise is executable">
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2064"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2063"/>
              <criterion comment="/usr/bin/pgmnoise is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2062"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmnorm is executable">
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2061"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2060"/>
              <criterion comment="/usr/bin/pgmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2059"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmoil is executable">
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2058"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2057"/>
              <criterion comment="/usr/bin/pgmoil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2056"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmramp is executable">
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2055"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2054"/>
              <criterion comment="/usr/bin/pgmramp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2053"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmslice is executable">
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2052"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2051"/>
              <criterion comment="/usr/bin/pgmslice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2050"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtexture is executable">
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2049"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2048"/>
              <criterion comment="/usr/bin/pgmtexture is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2047"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtofs is executable">
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2046"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2045"/>
              <criterion comment="/usr/bin/pgmtofs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2044"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtolispm is executable">
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2043"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2042"/>
              <criterion comment="/usr/bin/pgmtolispm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2041"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtopbm is executable">
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2040"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2039"/>
              <criterion comment="/usr/bin/pgmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2038"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pgmtoppm is executable">
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2037"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2036"/>
              <criterion comment="/usr/bin/pgmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2035"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi1toppm is executable">
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2034"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2033"/>
              <criterion comment="/usr/bin/pi1toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2032"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pi3topbm is executable">
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2031"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2030"/>
              <criterion comment="/usr/bin/pi3topbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2029"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pjtoppm is executable">
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2028"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2027"/>
              <criterion comment="/usr/bin/pjtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2026"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pktopbm is executable">
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2025"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2024"/>
              <criterion comment="/usr/bin/pktopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2023"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pngtopnm is executable">
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2022"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2021"/>
              <criterion comment="/usr/bin/pngtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2020"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmalias is executable">
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2019"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2018"/>
              <criterion comment="/usr/bin/pnmalias is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2017"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmarith is executable">
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2016"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2015"/>
              <criterion comment="/usr/bin/pnmarith is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2014"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcat is executable">
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2013"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2012"/>
              <criterion comment="/usr/bin/pnmcat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2011"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcolormap is executable">
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2010"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2009"/>
              <criterion comment="/usr/bin/pnmcolormap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2008"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcomp is executable">
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2007"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2006"/>
              <criterion comment="/usr/bin/pnmcomp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2005"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmconvol is executable">
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2004"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2003"/>
              <criterion comment="/usr/bin/pnmconvol is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2002"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcrop is executable">
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2001"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2000"/>
              <criterion comment="/usr/bin/pnmcrop is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1999"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmcut is executable">
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1998"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1997"/>
              <criterion comment="/usr/bin/pnmcut is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1996"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmdepth is executable">
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1995"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1994"/>
              <criterion comment="/usr/bin/pnmdepth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1993"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmenlarge is executable">
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1992"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1991"/>
              <criterion comment="/usr/bin/pnmenlarge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1990"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmfile is executable">
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1989"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1988"/>
              <criterion comment="/usr/bin/pnmfile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1987"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmflip is executable">
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1986"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1985"/>
              <criterion comment="/usr/bin/pnmflip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1984"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmgamma is executable">
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1983"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1982"/>
              <criterion comment="/usr/bin/pnmgamma is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1981"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhisteq is executable">
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1980"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1979"/>
              <criterion comment="/usr/bin/pnmhisteq is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1978"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmhistmap is executable">
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1977"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1976"/>
              <criterion comment="/usr/bin/pnmhistmap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1975"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminterp is executable">
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1974"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1973"/>
              <criterion comment="/usr/bin/pnminterp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1972"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnminvert is executable">
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1971"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1970"/>
              <criterion comment="/usr/bin/pnminvert is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1969"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmmontage is executable">
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1968"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1967"/>
              <criterion comment="/usr/bin/pnmmontage is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1966"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnlfilt is executable">
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1965"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1964"/>
              <criterion comment="/usr/bin/pnmnlfilt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1963"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmnoraw is executable">
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1962"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1961"/>
              <criterion comment="/usr/bin/pnmnoraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1960"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpad is executable">
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1959"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1958"/>
              <criterion comment="/usr/bin/pnmpad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1957"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpaste is executable">
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1956"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1955"/>
              <criterion comment="/usr/bin/pnmpaste is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1954"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmpsnr is executable">
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1953"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1952"/>
              <criterion comment="/usr/bin/pnmpsnr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1951"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmremap is executable">
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1950"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1949"/>
              <criterion comment="/usr/bin/pnmremap is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1948"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmrotate is executable">
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1947"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1946"/>
              <criterion comment="/usr/bin/pnmrotate is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1945"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscale is executable">
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1944"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1943"/>
              <criterion comment="/usr/bin/pnmscale is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1942"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopict is executable">
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1941"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1940"/>
              <criterion comment="/usr/bin/ppmtopict is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1939"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopj is executable">
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1938"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1937"/>
              <criterion comment="/usr/bin/ppmtopj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1936"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopjxl is executable">
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1935"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1934"/>
              <criterion comment="/usr/bin/ppmtopjxl is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1933"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopuzz is executable">
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1932"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1931"/>
              <criterion comment="/usr/bin/ppmtopuzz is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1930"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtorgb3 is executable">
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1929"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1928"/>
              <criterion comment="/usr/bin/ppmtorgb3 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1927"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtosixel is executable">
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1926"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1925"/>
              <criterion comment="/usr/bin/ppmtosixel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1924"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtotga is executable">
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1923"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1922"/>
              <criterion comment="/usr/bin/ppmtotga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1921"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtouil is executable">
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1920"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1919"/>
              <criterion comment="/usr/bin/ppmtouil is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1918"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtowinicon is executable">
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1917"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1916"/>
              <criterion comment="/usr/bin/ppmtowinicon is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1915"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoxpm is executable">
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1914"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1913"/>
              <criterion comment="/usr/bin/ppmtoxpm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1912"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuv is executable">
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1911"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1910"/>
              <criterion comment="/usr/bin/ppmtoyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1909"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoyuvsplit is executable">
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1908"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1907"/>
              <criterion comment="/usr/bin/ppmtoyuvsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1906"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtv is executable">
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1905"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1904"/>
              <criterion comment="/usr/bin/ppmtv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1903"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/psidtopgm is executable">
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1902"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1901"/>
              <criterion comment="/usr/bin/psidtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1900"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pstopnm is executable">
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1899"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1898"/>
              <criterion comment="/usr/bin/pstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1897"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/qrttoppm is executable">
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1896"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1895"/>
              <criterion comment="/usr/bin/qrttoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1894"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rasttopnm is executable">
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1893"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1892"/>
              <criterion comment="/usr/bin/rasttopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1891"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtopgm is executable">
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1890"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1889"/>
              <criterion comment="/usr/bin/rawtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1888"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rawtoppm is executable">
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1887"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1886"/>
              <criterion comment="/usr/bin/rawtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1885"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rgb3toppm is executable">
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1884"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1883"/>
              <criterion comment="/usr/bin/rgb3toppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1882"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/rletopnm is executable">
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1881"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1880"/>
              <criterion comment="/usr/bin/rletopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1879"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sbigtopgm is executable">
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1878"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1877"/>
              <criterion comment="/usr/bin/sbigtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1876"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sgitopnm is executable">
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1875"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1874"/>
              <criterion comment="/usr/bin/sgitopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1873"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sirtopnm is executable">
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1872"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1871"/>
              <criterion comment="/usr/bin/sirtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1870"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sldtoppm is executable">
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1869"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1868"/>
              <criterion comment="/usr/bin/sldtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1867"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spctoppm is executable">
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1866"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1865"/>
              <criterion comment="/usr/bin/spctoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1864"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/spottopgm is executable">
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1863"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1862"/>
              <criterion comment="/usr/bin/spottopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1861"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/sputoppm is executable">
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1860"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1859"/>
              <criterion comment="/usr/bin/sputoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1858"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tgatoppm is executable">
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1857"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1856"/>
              <criterion comment="/usr/bin/tgatoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1855"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/thinkjettopbm is executable">
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1854"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1853"/>
              <criterion comment="/usr/bin/thinkjettopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1852"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/tifftopnm is executable">
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1851"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1850"/>
              <criterion comment="/usr/bin/tifftopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1849"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/wbmptopbm is executable">
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1848"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1847"/>
              <criterion comment="/usr/bin/wbmptopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1846"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/winicontoppm is executable">
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1845"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1844"/>
              <criterion comment="/usr/bin/winicontoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1843"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xbmtopbm is executable">
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1842"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1841"/>
              <criterion comment="/usr/bin/xbmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1840"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ximtoppm is executable">
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1839"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1838"/>
              <criterion comment="/usr/bin/ximtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1837"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xpmtoppm is executable">
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1836"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1835"/>
              <criterion comment="/usr/bin/xpmtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1834"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xvminitoppm is executable">
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1833"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1832"/>
              <criterion comment="/usr/bin/xvminitoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1831"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xwdtopnm is executable">
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1830"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1829"/>
              <criterion comment="/usr/bin/xwdtopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1828"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ybmtopbm is executable">
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1827"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1826"/>
              <criterion comment="/usr/bin/ybmtopbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1825"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvsplittoppm is executable">
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1824"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1823"/>
              <criterion comment="/usr/bin/yuvsplittoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1822"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/yuvtoppm is executable">
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1821"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1820"/>
              <criterion comment="/usr/bin/yuvtoppm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1819"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/zeisstopnm is executable">
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1818"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1817"/>
              <criterion comment="/usr/bin/zeisstopnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1816"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmscalefixed is executable">
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1815"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1814"/>
              <criterion comment="/usr/bin/pnmscalefixed is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1813"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmshear is executable">
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1812"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1811"/>
              <criterion comment="/usr/bin/pnmshear is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1810"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsmooth is executable">
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1809"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1808"/>
              <criterion comment="/usr/bin/pnmsmooth is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1807"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmsplit is executable">
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1806"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1805"/>
              <criterion comment="/usr/bin/pnmsplit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1804"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtile is executable">
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1803"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1802"/>
              <criterion comment="/usr/bin/pnmtile is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1801"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoddif is executable">
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1800"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1799"/>
              <criterion comment="/usr/bin/pnmtoddif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1798"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofiasco is executable">
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1797"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1796"/>
              <criterion comment="/usr/bin/pnmtofiasco is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1795"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtofits is executable">
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1794"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1793"/>
              <criterion comment="/usr/bin/pnmtofits is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1792"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtojpeg is executable">
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1791"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1790"/>
              <criterion comment="/usr/bin/pnmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1789"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopalm is executable">
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1788"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1787"/>
              <criterion comment="/usr/bin/pnmtopalm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1786"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoplainpnm is executable">
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1785"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1784"/>
              <criterion comment="/usr/bin/pnmtoplainpnm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1783"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtopng is executable">
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1782"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1781"/>
              <criterion comment="/usr/bin/pnmtopng is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1780"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtops is executable">
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1779"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1778"/>
              <criterion comment="/usr/bin/pnmtops is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1777"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorast is executable">
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1776"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1775"/>
              <criterion comment="/usr/bin/pnmtorast is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1774"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtorle is executable">
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1773"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1772"/>
              <criterion comment="/usr/bin/pnmtorle is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1771"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosgi is executable">
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1770"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1769"/>
              <criterion comment="/usr/bin/pnmtosgi is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1768"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtosir is executable">
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1767"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1766"/>
              <criterion comment="/usr/bin/pnmtosir is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1765"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiff is executable">
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1764"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1763"/>
              <criterion comment="/usr/bin/pnmtotiff is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1762"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtotiffcmyk is executable">
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1761"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1760"/>
              <criterion comment="/usr/bin/pnmtotiffcmyk is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1759"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/pnmtoxwd is executable">
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1758"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1757"/>
              <criterion comment="/usr/bin/pnmtoxwd is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1756"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppm3d is executable">
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1755"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1754"/>
              <criterion comment="/usr/bin/ppm3d is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1753"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmbrighten is executable">
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1752"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1751"/>
              <criterion comment="/usr/bin/ppmbrighten is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1750"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmchange is executable">
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1749"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1748"/>
              <criterion comment="/usr/bin/ppmchange is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1747"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcie is executable">
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1746"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1745"/>
              <criterion comment="/usr/bin/ppmcie is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1744"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolormask is executable">
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1743"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1742"/>
              <criterion comment="/usr/bin/ppmcolormask is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1741"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmcolors is executable">
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1740"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1739"/>
              <criterion comment="/usr/bin/ppmcolors is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1738"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdim is executable">
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1737"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1736"/>
              <criterion comment="/usr/bin/ppmdim is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1735"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdist is executable">
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1734"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1733"/>
              <criterion comment="/usr/bin/ppmdist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1732"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmdither is executable">
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1731"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1730"/>
              <criterion comment="/usr/bin/ppmdither is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1729"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmflash is executable">
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1728"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1727"/>
              <criterion comment="/usr/bin/ppmflash is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1726"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmforge is executable">
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1725"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1724"/>
              <criterion comment="/usr/bin/ppmforge is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1723"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmhist is executable">
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1722"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1721"/>
              <criterion comment="/usr/bin/ppmhist is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1720"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmlabel is executable">
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1719"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1718"/>
              <criterion comment="/usr/bin/ppmlabel is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1717"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmake is executable">
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1716"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1715"/>
              <criterion comment="/usr/bin/ppmmake is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1714"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmmix is executable">
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1713"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1712"/>
              <criterion comment="/usr/bin/ppmmix is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1711"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmnorm is executable">
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1710"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1709"/>
              <criterion comment="/usr/bin/ppmnorm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1708"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmntsc is executable">
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1707"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1706"/>
              <criterion comment="/usr/bin/ppmntsc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1705"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmpat is executable">
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1704"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1703"/>
              <criterion comment="/usr/bin/ppmpat is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1702"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmquant is executable">
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1701"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1700"/>
              <criterion comment="/usr/bin/ppmquant is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1699"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmqvga is executable">
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1698"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1697"/>
              <criterion comment="/usr/bin/ppmqvga is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1696"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmrelief is executable">
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1695"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1694"/>
              <criterion comment="/usr/bin/ppmrelief is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1693"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmshift is executable">
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1692"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1691"/>
              <criterion comment="/usr/bin/ppmshift is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1690"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmspread is executable">
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1689"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1688"/>
              <criterion comment="/usr/bin/ppmspread is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1687"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoacad is executable">
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1686"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1685"/>
              <criterion comment="/usr/bin/ppmtoacad is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1684"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtobmp is executable">
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1683"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1682"/>
              <criterion comment="/usr/bin/ppmtobmp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1681"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoeyuv is executable">
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1680"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1679"/>
              <criterion comment="/usr/bin/ppmtoeyuv is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1678"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtogif is executable">
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1677"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1676"/>
              <criterion comment="/usr/bin/ppmtogif is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1675"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoicr is executable">
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1674"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1673"/>
              <criterion comment="/usr/bin/ppmtoicr is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1672"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoilbm is executable">
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1671"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1670"/>
              <criterion comment="/usr/bin/ppmtoilbm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1669"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtojpeg is executable">
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1668"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1667"/>
              <criterion comment="/usr/bin/ppmtojpeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1666"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoleaf is executable">
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1665"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1664"/>
              <criterion comment="/usr/bin/ppmtoleaf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1663"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtolj is executable">
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1662"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1661"/>
              <criterion comment="/usr/bin/ppmtolj is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1660"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtomitsu is executable">
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1659"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1658"/>
              <criterion comment="/usr/bin/ppmtomitsu is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1657"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtompeg is executable">
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1656"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1655"/>
              <criterion comment="/usr/bin/ppmtompeg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1654"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtoneo is executable">
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1653"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1652"/>
              <criterion comment="/usr/bin/ppmtoneo is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1651"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopcx is executable">
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1650"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1649"/>
              <criterion comment="/usr/bin/ppmtopcx is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1648"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopgm is executable">
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1647"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1646"/>
              <criterion comment="/usr/bin/ppmtopgm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1645"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ppmtopi1 is executable">
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1644"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1643"/>
              <criterion comment="/usr/bin/ppmtopi1 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1642"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:803" version="1" class="vulnerability">
      <metadata>
        <title>RedHat Code Execution and DoS Vulnerabilities in PWLib</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>PWLib</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0097" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0097"/>
        <description>Multiple vulnerabilities in PWLib before 1.6.0 allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Added a program_name element to rlt-217">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pwlib version is less than 1.4.7-4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2321"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="a program is listening on TCP or UDP port 1720" negate="false" test_ref="oval:org.mitre.oval:tst:2320"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:802" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of wins.exe is less than 5.2.3790.99" negate="false" test_ref="oval:org.mitre.oval:tst:2322"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:801" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Terminal Server WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 4.0.1381.33554" negate="false" test_ref="oval:org.mitre.oval:tst:2323"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:800" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:01.622-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of wins.exe is less than 4.0.1381.7255" negate="false" test_ref="oval:org.mitre.oval:tst:2324"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:80" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2969"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:8" version="2">
      <metadata>
        <title>SMB Rename Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-4696" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4696" source="CVE"/>
        <description>Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:51.510-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:02.463-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Srv.sys is less than 5.0.2195.7106" test_ref="oval:org.mitre.oval:tst:37"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Srv.sys is less than 5.1.2600.1885" test_ref="oval:org.mitre.oval:tst:39"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Srv.sys is less than 5.1.2600.2974" test_ref="oval:org.mitre.oval:tst:111"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:41"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:799" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of msasn1.dll is less than 5.2.3790.88" negate="false" test_ref="oval:org.mitre.oval:tst:2325"/>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:798" version="2" class="vulnerability">
      <metadata>
        <title>Office 2002 Remote Code Execution via Malformed Routing Slip</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009"/>
        <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on ste:2179 (referenced by tst:2327) changed to pattern match, per Rob Hollis.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.063-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2327"/>
        <criterion comment="the version of Winword.exe is less than 10.0.6775.0" negate="false" test_ref="oval:org.mitre.oval:tst:2326"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:797" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:28:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="a vulnerable version of msasn1.dll exists">
          <criteria operator="AND" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.119">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of msasn1.dll is less than 5.1.2600.119" negate="false" test_ref="oval:org.mitre.oval:tst:2329"/>
          </criteria>
          <criteria operator="AND" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1274">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of msasn1.dll is less than 5.1.2600.1274" negate="false" test_ref="oval:org.mitre.oval:tst:2328"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:796" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6824" negate="false" test_ref="oval:org.mitre.oval:tst:2330"/>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:795" version="2" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for JScript v5.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T11:01:00.000-04:00" comment="Added patch information to definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:38.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.5.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2906"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.5.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2902"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:794" version="2" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for JScript v5.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T11:02:00.000-04:00" comment="Added patch information to definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:53.836-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.1.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2907"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.1.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2903"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:793" version="1" class="vulnerability">
      <metadata>
        <title>IE6:XP,SP2 Java Proxy COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2087"/>
        <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-26T09:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-04T08:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false" test_ref="oval:org.mitre.oval:tst:2331"/>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:792" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Double Byte Character Parsing Memory Corruption (Win2K/WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1189"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with double-byte characters, aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:791" version="1" class="vulnerability">
      <metadata>
        <title>IE6 COM Object Instantiation Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7906" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:790" version="1" class="vulnerability">
      <metadata>
        <title>IE6:Server 2003 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.373" negate="false" test_ref="oval:org.mitre.oval:tst:2335"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
            </criteria>
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:79" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 RWall Daemon Syslog Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>rpc.rwalld</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0573"/>
        <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.rwalld exists" negate="false" test_ref="oval:org.mitre.oval:tst:3032"/>
          <criterion comment="Patch 112846-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2970"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.rwalld" negate="false" test_ref="oval:org.mitre.oval:tst:3030"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.rwalld executable">
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3029"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3028"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3027"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:789" version="2" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE6,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:38.339-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:787" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Parsing Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1185"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7865" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:20:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:786" version="1" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="netman.dll is less than 5.2.3790.2516" negate="false" test_ref="oval:org.mitre.oval:tst:2340"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:785" version="1" class="vulnerability">
      <metadata>
        <title>usermod Recursive Ownership Error (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00614838"/>
        <description>A security flaw in some versions of the HP-UX usermod command can result in recursively changing the ownership of all directories and files under a user's home directory.  Specifically, executing	# usermod -d &lt;old home dir> -u &lt;new gid> -m &lt;username> or	# usermod -d &lt;old home dir> -u &lt;new or old gid> -m &lt;username> incorrectly changes ownership recursively to &lt;username>.  If the home directory is '/', this action will render the system inoperable.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Patch PHCO_29269, PHCO_30275, or PHCO_32181 has been installed">
          <criterion comment="Patch PHCO_29269 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2344"/>
          <criterion comment="Patch PHCO_30275 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2343"/>
          <criterion comment="Patch PHCO_32181 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2342"/>
        </criteria>
        <criterion comment="Patch PHSS_34169 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2341"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:784" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Telnet Environment Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Services for UNIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
        <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the patch KB896428 for Services for UNIX is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2351"/>
        <criteria operator="OR" comment="Services for UNIX is instaled and a vulnerable version of telnet.exe exists">
          <criteria operator="AND" comment="Services for UNIX version 2.2 and telnet.exe version less than 5.3000.2073.13">
            <criterion comment="the version of telnet.exe is less than 5.3000.2073.13" negate="false" test_ref="oval:org.mitre.oval:tst:2350"/>
            <criterion comment="the software Services for UNIX is installed and the version is 2.2" negate="false" test_ref="oval:org.mitre.oval:tst:2349"/>
          </criteria>
          <criteria operator="AND" comment="Services for UNIX version 3.0 and telnet.exe version less than 7.0.1701.44">
            <criterion comment="the software Services for UNIX is installed and the version is 3.0" negate="false" test_ref="oval:org.mitre.oval:tst:2348"/>
            <criterion comment="the version of telnet.exe is less than 7.0.1701.44" negate="false" test_ref="oval:org.mitre.oval:tst:2347"/>
          </criteria>
          <criteria operator="AND" comment="Services for UNIX version 3.5 and telnet.exe version less than 8.0.1969.33">
            <criterion comment="the software Services for UNIX is installed and the version is 3.5" negate="false" test_ref="oval:org.mitre.oval:tst:2346"/>
            <criterion comment="the version of telnet.exe is less than 8.0.1969.33" negate="false" test_ref="oval:org.mitre.oval:tst:2345"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:783" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.701-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.880-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4033"/>
        <criterion comment="any SP is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3429"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.2.3790.360" negate="false" test_ref="oval:org.mitre.oval:tst:3457"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:782" version="2" class="vulnerability">
      <metadata>
        <title>IE6 for Server 2003 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T04:52:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="updated description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:59.058-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.327" negate="false" test_ref="oval:org.mitre.oval:tst:2501"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" negate="false" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
            <criteria operator="AND" comment="    a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" negate="false" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:781" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 InstallVersion.compareTo() DoS and Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2265"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:780" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Path MTU Discovery Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:01.450-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false" test_ref="oval:org.mitre.oval:tst:2354"/>
          <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
          <criterion comment="the patch KB893066 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2353"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Enable Path MTU Discovery is Disabled" negate="false" test_ref="oval:org.mitre.oval:tst:2352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:78" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Directory Traversal Command Execution (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" negate="false" test_ref="oval:org.mitre.oval:tst:2971"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:779" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Kernel Debugger-based Buffer Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" negate="false" test_ref="oval:org.mitre.oval:tst:2355"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:778" version="1" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6987" negate="false" test_ref="oval:org.mitre.oval:tst:2357"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:777" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 CSRSS Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Client Server Runtime System (CSRSS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
        <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:776" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2359"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:775" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft MDAC 2.8 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Data Access Compnents 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.8 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
        <criterion comment="the version of odbcbcp.dll is less than 2000.85.1025.0" negate="false" test_ref="oval:org.mitre.oval:tst:2362"/>
        <criterion comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" negate="false" test_ref="oval:org.mitre.oval:tst:2361"/>
        <criteria operator="OR" comment="the patch q832483 is not installed">
          <criteria operator="AND" comment="32-bit edition of windows and patch q832483 is not installed">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
          </criteria>
          <criteria operator="AND" comment="64-bit edition of windows and patch q832483 is not installed">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2360"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:774" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:773" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7721" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:772" version="1" class="vulnerability">
      <metadata>
        <title>usermod Recursive Ownership Error (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00614838"/>
        <description>'A security flaw in some versions of the HP-UX usermod command can result in recursively changing the ownership of all directories and files under a user\'s home directory.  Specifically, executing # usermod -d &lt;old home dir> -u &lt;new gid> -m &lt;username> or # usermod -d &lt;old home dir> -u &lt;new or old gid> -m &lt;username> incorrectly changes ownership recursively to &lt;username>.  If the home directory is \'/\', this action will render the system inoperable.'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7717" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:770" version="2" class="vulnerability">
      <metadata>
        <title>IE6,SP1 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T09:24:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:58.160-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2365"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2364"/>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:77" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false" test_ref="oval:org.mitre.oval:tst:3075"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:769" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows Server 2003 with Service Pack 1">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="the version of mscms.dll is less than 5.2.3790.2476" negate="false" test_ref="oval:org.mitre.oval:tst:2366"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:767" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.10.01, B.10.10)</title>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2373"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2372"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2371"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2370"/>
        </criteria>
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01 or 10.10">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01">
            <criteria operator="AND" comment="700 Series OS Release 10.01">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:2369"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.01">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:2369"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.10">
            <criteria operator="AND" comment="700 Series OS Release 10.10">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:2368"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.10">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:2368"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_23947 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2367"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:766" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd Remote Unauthorized Access (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>remshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.00) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2376"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2375"/>
        </criteria>
        <criterion comment="Patch PHNE_33790 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2374"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:765" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988"/>
        <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.441-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.590-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:763" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2002 Remote Code Execution via Malformed Record</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031"/>
        <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2377) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:1360 (referenced by tst:2378) fixed: was pattern match, now equals.  Thanks to John Hoyland of Centenial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:53.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2378"/>
        <criterion comment="the version of excel.exe is less than 10.0.6789.0" negate="false" test_ref="oval:org.mitre.oval:tst:2377"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7611" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T02:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:37.703-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:760" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Byte-range DoS Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:76" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Process Handle Duplication Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0367"/>
        <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" negate="false" test_ref="oval:org.mitre.oval:tst:2973"/>
        <criterion comment="Patch Q320206 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2972"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:759" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:755" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <platform>Sun Solaris 9</platform>
          <product>Access Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0531"/>
        <description>Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:53.102-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="x86" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        <criterion comment="Sun Java System Access Manager 7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3551"/>
        <criterion comment="Patch 120955-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3363"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:752" version="2">
      <metadata>
        <title>Microsoft Excel Malformed LABEL record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1309" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1309" source="CVE"/>
        <description>Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:37.395-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.031-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:751" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft MDAC 2.7 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Compnents 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="MDAC 2.7 is installed and a vulnerable version of sqlsrv32.dll and odbcbcp.dll exists">
          <criteria operator="AND" comment="MDAC 2.7 (RTM) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9002.0">
            <criterion comment="MDAC 2.7 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2590"/>
            <criterion comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" negate="false" test_ref="oval:org.mitre.oval:tst:2384"/>
            <criterion comment="the version of odbcbcp.dll is less than 2000.81.9002.0" negate="false" test_ref="oval:org.mitre.oval:tst:2383"/>
          </criteria>
          <criteria operator="AND" comment="MDAC 2.7 (SP1) is installed and both sqlsrv32.dll and odbcbcp.dll are less than 2000.81.9042.0">
            <criterion comment="MDAC 2.7 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2382"/>
            <criterion comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" negate="false" test_ref="oval:org.mitre.oval:tst:2381"/>
            <criterion comment="the version of odbcbcp.dll is less than 2000.81.9042.0" negate="false" test_ref="oval:org.mitre.oval:tst:2380"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:75" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal 0.9.12 Vulnerability in DCERPC Dissector</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0428"/>
        <description>Unknown vulnerability in the DCERPC (DCE/RPC) dissector in Ethereal 0.9.12 and earlier allows remote attackers to cause a denial of service (memory consumption) via a certain NDR string.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7496" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP2 for Server 2003 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:40:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 2 for XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:269"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than  6.0.2900.2523" negate="false" test_ref="oval:org.mitre.oval:tst:268"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than  6.0.2900.2524" negate="false" test_ref="oval:org.mitre.oval:tst:267"/>
          </criteria>
          <criterion comment="the patch kb834707  is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:266"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:749" version="1" class="vulnerability">
      <metadata>
        <title>bzip2 Decompression Bomb</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>bzip2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1260"/>
        <description>bzip2 allows remote attackers to cause a denial of service (hard drive consumption) via a crafted bzip2 file that causes an infinite loop (a.k.a "decompression bomb").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false" test_ref="oval:org.mitre.oval:tst:2386"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/bzip2 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2385"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:747" version="2">
      <metadata>
        <title>Winsock Hostname Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3440" source="CVE"/>
        <description>Buffer overflow in the Winsock API in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka "Winsock Hostname Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:37.143-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.747-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dnsapi.dll is less than 5.0.2195.7100" test_ref="oval:org.mitre.oval:tst:130"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.1863" test_ref="oval:org.mitre.oval:tst:81"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.2938" test_ref="oval:org.mitre.oval:tst:198"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:159"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:745" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:51:00.000-04:00" comment="modified wft-93 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false" test_ref="oval:org.mitre.oval:tst:2580"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7448" version="1" class="vulnerability">
      <metadata>
        <title>Oracle 9i XDB Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-14T11:25:00.000-04:00" comment="correct CVE from CAN-2003-0727 to CAN-2004-0727">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-12-14T11:27:00.000-04:00" comment="Fixed CVE reference; was CVE-2003-0727 because of a typo.  Now correctly refers to CVE-2004-0727.  Thanks to Andrew Simmons of MessageLabs for pointing out the error.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-12-16T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:744" version="1" class="vulnerability">
      <metadata>
        <title>Gaim DoS via Yahoo! Message</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1269"/>
        <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (application crash) via a Yahoo! message with non-ASCII characters in a file name.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false" test_ref="oval:org.mitre.oval:tst:2740"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/gaim is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:743" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-03-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2003-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:50:00.000-04:00" comment="modified wft-114 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-31 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
            <criterion comment="the version of fp4areg.dll is less than 4.0.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2681"/>
            <criterion comment="the version of fp30reg.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2680"/>
          </criteria>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:742" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Improper Handling of Synthetic Events in Mozilla</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2260"/>
        <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:740" version="2">
      <metadata>
        <title>Microsoft Office Smart Tag Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-3868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3868" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:50.786-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:01.634-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2002" operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6817.0" test_ref="oval:org.mitre.oval:tst:158"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8107.0" test_ref="oval:org.mitre.oval:tst:98"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:74" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE dtspcd Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803"/>
        <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File dtspcd exists" negate="false" test_ref="oval:org.mitre.oval:tst:2983"/>
          <criterion comment="Patch 106934-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2974"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains dtspcd" negate="false" test_ref="oval:org.mitre.oval:tst:2981"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File dtspcd executable">
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2980"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2979"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2978"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:738" version="2">
      <metadata>
        <title>Redirect Cross-Domain Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3280" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3280" source="CVE"/>
        <description>Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, aka "Redirect Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:36.755-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.367-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:736" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Kerberos</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1175" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1175"/>
        <description>Heap-based buffer overflow in the Key Distribution Center (KDC) in MIT Kerberos 5 (krb5) 1.4.1 and earlier allows remote attackers to cause a denial of service (apllication crash) and possibly execute arbitrary code via a certain valid TCP or UDP request.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.863-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:00.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112536-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112537-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3424"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112237-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3567"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112238-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3898"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112390-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3640"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112240-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112908-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3389"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 115168-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3624"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120469-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3561"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120470-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:735" version="1" class="vulnerability">
      <metadata>
        <title>Apache Integer Overflow in pcre_compile.c</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:733" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-21T05:00:00.000-04:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2663"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:73" version="1" class="vulnerability">
      <metadata>
        <title>Integer Overflow Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0357"/>
        <description>Multiple integer overflow vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) Mount and (2) PPP dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:729" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla DOM Node Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:728" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0448"/>
        <description>Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.495-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.663-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Perl 5.6 or 5.8 vulnerable on 11.00, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Perl version 5.6.0 is installed or 5.8.0 without revision G or later is installed" negate="false">
            <criterion comment="Perl 5.6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3419"/>
            <criterion comment="Perl 5.8.0 (revision F or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.00 or 11.11" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision C or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3226"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision E or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3635"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.3 vulnerable on 11.0, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.3,revision A is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:727" version="1" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in Office 2003 and Accessories</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Imekr70.ime is less than 7.0.8002.0 (Office 2003 and Accessories)" negate="false" test_ref="oval:org.mitre.oval:tst:2389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:726" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMPSource Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.288-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:724" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 7</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.045-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.217-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112536-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3544"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112537-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3498"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112237-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3354"/>
            <criterion comment="Patch 112390-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3509"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 112240-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3366"/>
            <criterion comment="Patch 112238-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4043"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3824"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101512 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 115168-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4066"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Target's configuration meets 101512 configuration criteria." negate="false">
            <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)" negate="false">
              <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3514"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3192"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3873"/>
              <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3369"/>
            </criteria>
            <criteria operator="AND" comment="SEAM is not installed, but target is a kerberos client." negate="false">
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)" negate="true">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3514"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3192"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3873"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:3369"/>
              </criteria>
              <criterion comment="/etc/krb5/krb5.conf is configured as a kerberos client" negate="false" test_ref="oval:org.mitre.oval:tst:3487"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:723" version="2">
      <metadata>
        <title>DNS Client Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3441" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3441" source="CVE"/>
        <description>Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response.  NOTE: while MS06-041 implies that there is a single issue, there are multiple vectors, and likely multiple vulnerabilities, related to (1) a heap-based buffer overflow in a DNS server response to the client, (2) a DNS server response with malformed ATMA records, and (3) a length miscalculation in TXT, HINFO, X25, and ISDN records.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:36.303-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.770-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dnsapi.dll is less than 5.0.2195.7100" test_ref="oval:org.mitre.oval:tst:130"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.1863" test_ref="oval:org.mitre.oval:tst:81"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of dnsapi.dll is less than 5.1.2600.2938" test_ref="oval:org.mitre.oval:tst:198"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:159"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dnsapi.dll is less than 5.2.3790.2745" test_ref="oval:org.mitre.oval:tst:51"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:722" version="1" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:721" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Web Client Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Web Client Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1207"/>
        <description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.316" negate="false" test_ref="oval:org.mitre.oval:tst:2392"/>
        <criterion comment="the patch kb896426 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:72" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Variant of Chunked Encoding Buffer Overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0147"/>
        <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7194" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T07:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:719" version="2">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3638" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3638" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnimation.DATuple ActiveX control, aka "COM Object Instantiation Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.956-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.310-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:717" version="1" class="vulnerability">
      <metadata>
        <title>gftp Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gftp</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0372"/>
        <description>Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-25T10:22:00.000-04:00" comment="modified upt-62 - Changed DATA operation to OR (to test for any exec bit set, not all).  Fixed typo in comment.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-01-25T07:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="gftp rpm is earlier than 1:2.0.14-4" negate="false" test_ref="oval:org.mitre.oval:tst:2394"/>
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="gftp is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2393"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:716" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:714" version="1" class="vulnerability">
      <metadata>
        <title>Win2k Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.0.2195.7071 or T2embed.dll &lt;5.0.2195.7073 (Win2k,SP4)">
          <criterion comment="the version of Fontsub.dll is less than 5.0.2195.7071" negate="false" test_ref="oval:org.mitre.oval:tst:2397"/>
          <criterion comment="the version of T2embed.dll is less than 5.0.2195.7073" negate="false" test_ref="oval:org.mitre.oval:tst:2396"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:713" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Hyperlink Object Library Unchecked Buffer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Hyperlink Object Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0057"/>
        <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-11T09:34:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of hlink.dll is less than 5.2.3790.227" negate="false" test_ref="oval:org.mitre.oval:tst:2399"/>
        <criterion comment="the patch kb888113 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2398"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:712" version="2" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.954-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of user32.dll is less than 4.0.1381.7342" negate="false" test_ref="oval:org.mitre.oval:tst:2400"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:711" version="1" class="vulnerability">
      <metadata>
        <title>ImageMagick Buffer Overflow in ReadPNMImage()</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>ImageMagick</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1275" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1275"/>
        <description>Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-28T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ImageMagick RPM earlier than 0:5.5.6-14" negate="false" test_ref="oval:org.mitre.oval:tst:2401"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:710" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-159 - unchecked value">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false" test_ref="oval:org.mitre.oval:tst:2402"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:71" version="1" class="vulnerability">
      <metadata>
        <title>Privilege Escalation Using Cached Admin Connection</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0344" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0344"/>
        <description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-06-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-07T12:00:00.000-04:00" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-04-07T09:25:00.000-04:00" comment="modified wft-222 - Corrected comment">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="the version of sqlservr.exe is less than 2000.80.296.0" negate="false" test_ref="oval:org.mitre.oval:tst:2976"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Mixed Mode Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7095" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
        <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7084" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:22:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:708" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="shell32.dll is less than 6.0.3790.2521" negate="false" test_ref="oval:org.mitre.oval:tst:2404"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:704" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 WINS Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0825" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0825"/>
        <description>The Windows Internet Naming Service (WINS) for Microsoft Windows Server 2003, and possibly Windows NT and Server 2000, does not properly validate the length of certain packets, which allows attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.642-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.0.2195.6870" negate="false" test_ref="oval:org.mitre.oval:tst:2407"/>
          <criterion comment="the patch kb830352 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2406"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:702" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Privilege Escalation/DoS Vulnerability (6293270)</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0190"/>
        <description>Unspecified vulnerability in Sun Solaris 9 and 10 for the x86 platform allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors, possibly involving functions from the mm driver.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102066 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Contributing factors for Solaris 9, Sun Alert ID 102066 criteria.">
            <criterion comment="Patch 112234-11 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2413"/>
            <criterion comment="Patch 112234-12 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2412"/>
            <criterion comment="Patch 117172-16 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:2411"/>
          </criteria>
          <criterion comment="Patch 118559-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2410"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118844-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:701" version="1" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (64-bit Windows XP and Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2542" negate="false" test_ref="oval:org.mitre.oval:tst:2414"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:70" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE dtspcd Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0803"/>
        <description>Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File dtspcd exists" negate="false" test_ref="oval:org.mitre.oval:tst:2983"/>
          <criterion comment="Patch 108949-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2982"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains dtspcd" negate="false" test_ref="oval:org.mitre.oval:tst:2981"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File dtspcd executable">
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2980"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2979"/>
            <criterion comment="File dtspcd executable" negate="false" test_ref="oval:org.mitre.oval:tst:2978"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:699" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-03-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2003-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:50:00.000-04:00" comment="modified wft-114 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-31 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
            <criterion comment="the version of fp4areg.dll is less than 4.0.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2681"/>
            <criterion comment="the version of fp30reg.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2680"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (WinNT)" negate="false" test_ref="oval:org.mitre.oval:tst:2526"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:698" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.2777 or T2embed.dll &lt;5.1.2600.2777 (WinXP,SP2)">
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.2777" negate="false" test_ref="oval:org.mitre.oval:tst:2416"/>
          <criterion comment="the version of T2embed.dll is less than 5.1.2600.2777" negate="false" test_ref="oval:org.mitre.oval:tst:2415"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:697" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:695" version="2" class="vulnerability">
      <metadata>
        <title>MS Excel 2002 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-16 - wft-16 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2419) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1377 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:51.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2420"/>
        <criterion comment="the version of excel.exe is less than 10.0.5815.0" negate="false" test_ref="oval:org.mitre.oval:tst:2419"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:694" version="2">
      <metadata>
        <title>Visual Basic for Applications Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Visual Basic</product>
        </affected>
        <reference ref_id="CVE-2006-3649" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3649" source="CVE"/>
        <description>Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.094-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.846-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Vbe6.dll is installed and has a version less than 6.4.99.72" test_ref="oval:org.mitre.oval:tst:94"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:690" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Temporary Internet Files folders Name Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1188"/>
        <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:69" version="1" class="vulnerability">
      <metadata>
        <title>Off-by-one Vulnerabilities in Ethereal 0.9.11</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0356"/>
        <description>Multiple off-by-one vulnerabilities in Ethereal 0.9.11 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via the (1) AIM, (2) GIOP Gryphon, (3) OSPF, (4) PPTP, (5) Quake, (6) Quake2, (7) Quake3, (8) Rsync, (9) SMB, (10) SMPP, and (11) TSP dissectors, which do not properly use the tvb_get_nstringz and tvb_get_nstringz0 functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:689" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:688" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.358-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:687" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:686" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:685" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed: Duplicate of OVAL1959</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-02-09T12:00:00.000-04:00" comment="modified cmp-35 - Corrected test comment">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-35 - wrt-35 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criterion comment="the version of mswrd6.wpc is less than 10.0.803.2" negate="false" test_ref="oval:org.mitre.oval:tst:2422"/>
          <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Word for Windows 6.0 Converter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2421"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:683" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of webclnt.dll is less than 5.1.2600.1790 (XP,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2423"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6829" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:682" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Agent Security Prompt Spoofing Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
        <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T07:25:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added cve description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-17T09:54:00.000-04:00" comment="Updated obj:1000 to use new variable var:759 for path reference rather than var:200.  Now uses 'msagent' subdir of SystemRoot instead of System32.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-11-17T09:54:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:54:00.438-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of agentdpv.dll is less than 2.0.0.3423" negate="false" test_ref="oval:org.mitre.oval:tst:2425"/>
          <criterion comment="the patch kb890046 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2424"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:681" version="1" class="vulnerability">
      <metadata>
        <title>Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>NetDDE Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1230"/>
        <description>NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T03:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of user32.dll is less than 4.0.1381.7177" negate="false" test_ref="oval:org.mitre.oval:tst:2430"/>
        <criterion comment="the version of gdi32.dll is less than 4.0.1381.7177" negate="false" test_ref="oval:org.mitre.oval:tst:2429"/>
        <criterion comment="the version of winsrv.dll is less than 4.0.1381.7202" negate="false" test_ref="oval:org.mitre.oval:tst:2428"/>
        <criterion comment="the version of win32k.sys is less than 4.0.1381.7207" negate="false" test_ref="oval:org.mitre.oval:tst:2427"/>
        <criterion comment="Patch Q328310 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2426"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:68" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 admintool Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0089"/>
        <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:25:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.775-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
          <criterion comment="Patch 108721-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2986"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6788" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (64-Bit) Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T04:23:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="a vulnerable version of netdde.exe exists">
          <criterion comment="the version of netdde.exe is less than 5.2.3790.184" negate="false" test_ref="oval:org.mitre.oval:tst:315"/>
          <criterion comment="the 64-bit WOW version of netdde.exe is less than 5.2.3790.193" negate="false" test_ref="oval:org.mitre.oval:tst:271"/>
        </criteria>
        <criteria operator="OR" comment="a vulnerable version of nddenb32.dll exists">
          <criterion comment="the version of nddenb32.dll is less than 5.2.3790.173" negate="false" test_ref="oval:org.mitre.oval:tst:316"/>
          <criterion comment="the 64-bit WOW version of nddenb32.dll is less than 5.2.3790.193" negate="false" test_ref="oval:org.mitre.oval:tst:270"/>
        </criteria>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:678" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP IGMP v3 Denial of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0021"/>
        <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2431"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:677" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla XML Parser Read Beyond Buffer Bug</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0298" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0298"/>
        <description>The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:676" version="1" class="vulnerability">
      <metadata>
        <title>PostgreSQL Character Conversion Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>postgresql</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1409" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1409"/>
        <description>PostgreSQL 7.3.x through 8.0.x gives public EXECUTE access to certain character conversion functions, which allows unprivileged users to call those functions with malicious values, with unknown impact, aka the "Character conversion vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="rh-postgresql-server is earlier than 0:7.3.10-1" negate="false" test_ref="oval:org.mitre.oval:tst:2433"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="postmaster (the PostgreSQL master daemon) is running" negate="false" test_ref="oval:org.mitre.oval:tst:2432"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:673" version="2">
      <metadata>
        <title>Windows 2000 Kernel Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3444" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3444" source="CVE"/>
        <description>Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, probably a buffer overflow, allows local users to obtain privileges via unspecified vectors involving an "unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:34.552-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of Ntoskrnl.exe is less than 5.0.2195.7098" test_ref="oval:org.mitre.oval:tst:46"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:671" version="1" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (64-bit Windows XP and Server 2003,Unpatched)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.419" negate="false" test_ref="oval:org.mitre.oval:tst:2436"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:670" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Garbage-Collection Hazards in jsinterp.c</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0292"/>
        <description>The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird pre-1.5 is installed without an upgraded Firefox (1.5.0.1)">
          <criterion comment="Mozilla Thunderbird pre-1.5" negate="false" test_ref="oval:org.mitre.oval:tst:2448"/>
          <criterion comment="Thunderbird pre-1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2447"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox pre-1.5 is installed">
          <criterion comment="Mozilla Firefox pre-1.5" negate="false" test_ref="oval:org.mitre.oval:tst:2445"/>
          <criterion comment="Firefox pre-1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2444"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite is installed">
          <criterion comment="Mozilla Suite installed" negate="false" test_ref="oval:org.mitre.oval:tst:2441"/>
          <criterion comment="Mozilla Suite is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2440"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:67" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 admintool Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0089"/>
        <description>Buffer overflow in admintool in Solaris 2.5 through 8 allows local users to gain root privileges via long arguments to (1) the -d command line option, or (2) the PRODVERS argument in the .cdtoc file.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:24:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.346-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
          <criterion comment="Patch 110453-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2987"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:668" version="2" class="vulnerability">
      <metadata>
        <title>MS Word 2002 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2003-11-19T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-22 by correcting literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.5815.0" negate="false" test_ref="oval:org.mitre.oval:tst:2449"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:667" version="1" class="vulnerability">
      <metadata>
        <title>ypserv NIS Server Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>ypserv</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0251" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0251"/>
        <description>ypserv NIS server before 2.7 allows remote attackers to cause a denial of service via a TCP client request that does not respond to the server, which causes ypserv to block.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ypserv version is less than 2.8-0.9E" negate="false" test_ref="oval:org.mitre.oval:tst:2451"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypserv is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2450"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:664" version="1" class="vulnerability">
      <metadata>
        <title>Code Execution Vulnerability in XPDF PDF Viewer</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xpdf</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0434"/>
        <description>Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xpdf version is less than 2.0.1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2455"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="xpdf is executable">
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2454"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2453"/>
            <criterion comment="xpdf is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2452"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:662" version="1" class="vulnerability">
      <metadata>
        <title>lpsched Local System Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0227" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0227"/>
        <description>Multiple unspecified vulnerabilities in lpsched in Sun Solaris 8, 9, and 10 allow local users to delete arbitrary files or disable the LP print service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-16T12:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109320-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2464"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109321-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2462"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113329-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2461"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 114980-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2460"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (sparc) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 120467-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2458"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102033 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 120468-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2457"/>
        </criteria>
        <criterion comment="Target is configured as a print server" negate="false" test_ref="oval:org.mitre.oval:tst:2456"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6600" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:23:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:66" version="1" class="vulnerability">
      <metadata>
        <title>IIS ASP Function Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0223" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0223"/>
        <description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:2988"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6579" version="1" class="vulnerability">
      <metadata>
        <title>Windows (ME, NT, 2K, XP), IE v6,SP1 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:56:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:657" version="1" class="vulnerability">
      <metadata>
        <title>xinitd Memory Leak Invites Denial of Service Attack</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>xinetd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0211"/>
        <description>Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large number of rejected connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-17T12:00:00.000-04:00" comment="Changed tested epoch in xinetd test rvt-253 to 2, based on testing.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="xinetd version is less than 2:2.3.11-1.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2467"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="xinetd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2466"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:653" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 ASN.1 Library Integer Overflow Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0818" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0818"/>
        <description>Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6823" negate="false" test_ref="oval:org.mitre.oval:tst:2469"/>
        <criterion comment="the patch kb828028 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:651" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.103-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.450-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:65" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 kcms_configure Command-Line Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_configure</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0594" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0594"/>
        <description>kcms_configure as included with Solaris 7 and 8 allows a local attacker to gain additional privileges via a buffer overflow in a command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File kcms_configure exists" negate="false" test_ref="oval:org.mitre.oval:tst:3144"/>
          <criterion comment="Patch 107337-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2989"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File kcms_configure executable and SUID or SGID">
            <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3143"/>
            <criteria operator="OR" comment="File kcms_configure executable and SUID or SGID">
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3142"/>
              <criterion comment="File kcms_configure executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:3141"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:648" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:50.907-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
        <criteria operator="OR" comment="Either PHNE_30983 or PHNE_31732 is installed" negate="true">
          <criterion comment="Patch PHNE_30983 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2471"/>
          <criterion comment="Patch PHNE_31732 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:647" version="1" class="vulnerability">
      <metadata>
        <title>mikmod Long Filename Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mikmod</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0427"/>
        <description>Buffer overflow in mikmod 3.1.6 and earlier allows remote attackers to execute arbitrary code via an archive file that contains a file with a long filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="mikmod RPM prior to 0:3.1.6-22.EL3" negate="false" test_ref="oval:org.mitre.oval:tst:2474"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mikmod is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2473"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:644" version="1" class="vulnerability">
      <metadata>
        <title>License Logging Service Vulnerability (Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>MDAC 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0050"/>
        <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
          <criterion comment="the patch kb885834 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2477"/>
          <criterion comment="the version of Llssrv.exe is less than 4.0.1381.33632" negate="false" test_ref="oval:org.mitre.oval:tst:2476"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="license logging service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:643" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:642" version="1" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.02)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version equal to A.02.01">
          <criterion comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2481"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2480"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2479"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2478"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:64" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Trusted Domain Loophole</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0018"/>
        <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:56:00.000-04:00" comment="modified wft-220 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" negate="false" test_ref="oval:org.mitre.oval:tst:2991"/>
        <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6397" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) DUNZIP Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Compressed Folders</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0575"/>
        <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-05T12:00:00.000-04:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          <criterion comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" negate="false" test_ref="oval:org.mitre.oval:tst:272"/>
          <criterion comment="the patch q873376 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1236"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Compressed Folders with zipfldr.dll are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1235"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:639" version="2">
      <metadata>
        <title>Microsoft Office Malformed String Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-1540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1540" source="CVE"/>
        <description>MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt.  NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:33.119-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.086-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Project 2002, SP1" operator="AND">
          <extend_definition comment="Microsoft Project 2002, SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Visio 2002" operator="AND">
          <extend_definition comment="Microsoft Visio 2002 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
        <criteria comment="Project 2000, SP1" operator="AND">
          <extend_definition comment="Microsoft Project 2000, SP1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Catch-all for the 2000 version of the Mso9.dll library." operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Catchall for the 2002 version of the Mso.dll library." operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Catchall for the 2003 version of the Mso.dll library." operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:638" version="2">
      <metadata>
        <title>MMC Redirect Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Management Console</product>
        </affected>
        <reference ref_id="CVE-2006-3643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3643" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resource files" in the Microsoft Management Console (MMC) library, which allows remote authenticated users to execute arbitrary commands, aka "MMC Redirect Cross-Site Scripting Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:32.866-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
        <criterion comment="the version of mmc.exe is less than 5.0.2195.7102" test_ref="oval:org.mitre.oval:tst:193"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:637" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:636" version="2" class="vulnerability">
      <metadata>
        <title>MS Excel 2000 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-15 - wft-15 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2484) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:50.673-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8216" negate="false" test_ref="oval:org.mitre.oval:tst:2484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:634" version="1" class="vulnerability">
      <metadata>
        <title>vsftpd Fails to Integrate with TCP Wrappers</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>vsftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0135" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0135"/>
        <description>vsftpd FTP daemon in Red Hat Linux 9 is not compiled against TCP wrappers (tcp_wrappers) but is installed as a standalone service, which inadvertently prevents vsftpd from restricting access as intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="vsftpd version is less than 1.1.3-8" negate="false" test_ref="oval:org.mitre.oval:tst:2487"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="vsftpd is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2486"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:632" version="2">
      <metadata>
        <title>Office Malformed Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-3864" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3864" source="CVE"/>
        <description>Unspecified vulnerability in mso.dll in Microsoft Office 2000, XP, and 2003, and Microsoft PowerPoint 2000, XP, and 2003, allows remote user-assisted attackers to execute arbitrary code via a malformed record in a (1) .DOC, (2) .PPT, or (3) .XLS file that triggers memory corruption, related to an "array boundary condition" (possibly an array index overflow), a different vulnerability than CVE-2006-3434, CVE-2006-3650, and CVE-2006-3868.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:49.961-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:00.469-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:33"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6817.0" test_ref="oval:org.mitre.oval:tst:158"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8107.0" test_ref="oval:org.mitre.oval:tst:98"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6313" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 for Server 2003 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:631" version="1" class="vulnerability">
      <metadata>
        <title>up2date RPM GPG Signature Verification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>up2date</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0546" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0546"/>
        <description>up2date 3.0.7 and 3.1.23 does not properly verify RPM GPG signatures, which could allow remote attackers to cause unsigned packages to be installed from the Red Hat Network, if that network is compromised.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-03T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="up2date version is less than 3.1.23.1-5" negate="false" test_ref="oval:org.mitre.oval:tst:2489"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rhnsd is running" negate="false" test_ref="oval:org.mitre.oval:tst:2488"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:630" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Travel Log Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1026"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added to the history list and executed in the top window's zone when the history.back (back) function is called, as demonstrated by BackToFramedJpu, aka the "Travel Log Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:63" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Remote Access Service Phonebook Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Access Service (RAS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0366"/>
        <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="RAS Phonebook" negate="false" test_ref="oval:org.mitre.oval:tst:2999"/>
          <criterion comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" negate="false" test_ref="oval:org.mitre.oval:tst:2992"/>
          <criterion comment="Patch Q318138 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2997"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RAS Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:629" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:54:00.000-04:00" comment="modified wft-95 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false" test_ref="oval:org.mitre.oval:tst:2572"/>
          <criterion comment="the patch q832894 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2571"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6272" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:624" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server 5.5 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange 5.5 with SP4 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2492"/>
        <criterion comment="the version of Mapi32.dll is less than 5.5.2658.34" negate="false" test_ref="oval:org.mitre.oval:tst:2491"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:623" version="1" class="vulnerability">
      <metadata>
        <title>sysreport Plaintext Password Leak</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>sysreport</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1760"/>
        <description>sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="sysreport RPM earlier than 0:1.3.7.2-6" negate="false" test_ref="oval:org.mitre.oval:tst:2494"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/tmp is world-writable" negate="false" test_ref="oval:org.mitre.oval:tst:2493"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:622" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.491-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.160-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118822-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 118844-28 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:62" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 mibiisa Remote Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>mibiisa</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0797"/>
        <description>Buffer overflow in the MIB parsing component of mibiisa for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File mibiisa exists" negate="false" test_ref="oval:org.mitre.oval:tst:2995"/>
          <criterion comment="Patch 107709-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mibiisa running" negate="false" test_ref="oval:org.mitre.oval:tst:2993"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:619" version="1" class="vulnerability">
      <metadata>
        <title>UnZip 5.0 Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>unzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0282"/>
        <description>Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="unzip version is less than 5.50-33" negate="false" test_ref="oval:org.mitre.oval:tst:2498"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/unzip is executable">
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2497"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2496"/>
            <criterion comment="/usr/bin/unzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2495"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:618" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.349-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.992-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3750"/>
        <criterion comment="SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3342"/>
        <criterion comment="64-bit version" negate="true" test_ref="oval:org.mitre.oval:tst:3257"/>
        <criterion comment="rdpwd.sys is less than 5.1.2600.1698" negate="false" test_ref="oval:org.mitre.oval:tst:3742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:616" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00622788"/>
        <description>An undisclosed vulnerability has been identified in swagentd that could potentially be exploited remotely by an unauthenticated attacker to cause swagentd to abort.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.134-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.789-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.11 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_29964 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_29964 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3974"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_28848 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_28848 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:615" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3641"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:614" version="1" class="vulnerability">
      <metadata>
        <title>SqirrelMail Cross-site Scripting Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0160"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail before 1.2.11 allow remote attackers to inject arbitrary HTML code and steal information from a client's web browser.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="squirrelmail version is less than 1.2.11-1" negate="false" test_ref="oval:org.mitre.oval:tst:2499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6100" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:610" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>Operating System</product>
        </affected>
        <description>An SCLT_INCOMPLETE error was blocking receipt of proper READY status from the array.  A timer was changed to allow array to reach full READY before SCSI response is tested.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.786-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.424-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.X" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.20" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.20" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.20" negate="false" test_ref="oval:org.mitre.oval:tst:3807"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.20" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.20" negate="false" test_ref="oval:org.mitre.oval:tst:3807"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.01" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.01" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:3581"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.01" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.01" negate="false" test_ref="oval:org.mitre.oval:tst:3581"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.10" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.10" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:3985"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.10" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.10" negate="false" test_ref="oval:org.mitre.oval:tst:3985"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.30" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 10.30" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.10.30" negate="false" test_ref="oval:org.mitre.oval:tst:3461"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 10.30" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.10.30" negate="false" test_ref="oval:org.mitre.oval:tst:3461"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ADMN-ENG-A-MAN or OS-Core.C2400-UTIL is installed" negate="false">
          <criterion comment="OS-Core.ADMN-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3370"/>
          <criterion comment="OS-Core.C2400-UTIL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3376"/>
        </criteria>
        <criterion comment="Patch PHCO_23261 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3674"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:61" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Remote Access Service Phonebook Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Access Service (RAS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0366" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0366"/>
        <description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="RAS Phonebook" negate="false" test_ref="oval:org.mitre.oval:tst:2999"/>
          <criterion comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" negate="false" test_ref="oval:org.mitre.oval:tst:2998"/>
          <criterion comment="Patch Q318138 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2997"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RAS Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:609" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.579-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.082-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4033"/>
        <criterion comment="any SP is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3429"/>
        <criterion comment="rdpwd.sys is less than 5.2.3790.348" negate="false" test_ref="oval:org.mitre.oval:tst:3978"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:608" version="1" class="vulnerability">
      <metadata>
        <title>IE6 for Server 2003 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.327" negate="false" test_ref="oval:org.mitre.oval:tst:2501"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" negate="false" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
            <criteria operator="AND" comment="    a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2440" negate="false" test_ref="oval:org.mitre.oval:tst:2500"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:606" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:51:00.000-04:00" comment="modified wft-12 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
          <criterion comment="the version of shtml.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2708"/>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:605" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Telnet Environment Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Services for UNIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
        <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of telnet.exe exists">
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of telnet.exe exists">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.329" negate="false" test_ref="oval:org.mitre.oval:tst:2504"/>
          </criteria>
          <criteria operator="AND" comment="  for specific Windows configurations a vulnerable version of telnet.exe exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.2442" negate="false" test_ref="oval:org.mitre.oval:tst:2503"/>
          </criteria>
          <criteria operator="AND" comment="  for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.2442" negate="false" test_ref="oval:org.mitre.oval:tst:2503"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB896428 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2502"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6048" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP4 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6031" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5, SP2 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T07:54:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:603" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail BO in prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:600" version="2">
      <metadata>
        <title>Mailslot Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating Ssytem</product>
        </affected>
        <reference ref_id="CVE-2006-1314" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1314" source="CVE"/>
        <description>Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:32.388-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7087" negate="false" test_ref="oval:org.mitre.oval:tst:64"/>
        </criteria>
        <criteria comment="WinXP,SP1 (32-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1832" negate="false" test_ref="oval:org.mitre.oval:tst:23"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2893" negate="false" test_ref="oval:org.mitre.oval:tst:127"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" negate="false" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.526" negate="false" test_ref="oval:org.mitre.oval:tst:97"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" negate="false" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:60" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 8 AdminTool Media Installation Path Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0088"/>
        <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:23:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:32.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6" version="1" class="vulnerability">
      <metadata>
        <title>CUPS Partial Print DOS</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CUPS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0195" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0195"/>
        <description>CUPS before 1.1.19 allows remote attackers to cause a denial of service via a partial printing request to the IPP port (631), which does not time out.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cups version is less than 1.1.17-13.3" negate="false" test_ref="oval:org.mitre.oval:tst:3147"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="cupsd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:3146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:598" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX xterm Local Unauthorized Access due to Bad Patch</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>remshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="X11.X11-RUN-CL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2510"/>
        <criteria operator="OR" comment="A vulnerable patch to xterm is installed">
          <criterion comment="Patch PHSS_32109 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2509"/>
          <criterion comment="Patch PHSS_30791 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2508"/>
          <criterion comment="Patch PHSS_33589 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2507"/>
          <criterion comment="Patch PHSS_31833 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2506"/>
          <criterion comment="Patch PHSS_32366 or later is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2505"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:597" version="1" class="vulnerability">
      <metadata>
        <title>Denial of Service in Sendmail via the enhdnsbl Feature</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0688"/>
        <description>The DNS map code in Sendmail 8.12.8 and earlier, when using the "enhdnsbl" feature, does not properly initialize certain data structures, which allows remote attackers to cause a denial of service (process crash) via an invalid DNS response that causes Sendmail to free incorrect data.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-6.90" negate="false" test_ref="oval:org.mitre.oval:tst:2517"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sendmail is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2516"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:596" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.438-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.897-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:595" version="1" class="vulnerability">
      <metadata>
        <title>Potential BO in Ruleset Parsing for Sendmail</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0681" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0681"/>
        <description>A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-9.90" negate="false" test_ref="oval:org.mitre.oval:tst:2518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:594" version="1" class="vulnerability">
      <metadata>
        <title>Windows Messenger 6 libpng Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-11-24T12:00:00.000-04:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-195 to check for 6.2.0205 or later.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Added wrt-195.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MSN Messenger 6.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2520"/>
        <criterion comment="MSN Messenger 6.2.0205 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2519"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:593" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.302-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.23 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3687"/>
        <criterion comment="Patch PHNE_33414 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3428"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5926" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 NNTP Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0574"/>
        <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T08:58:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:59.853-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of nntpsvc.dll is less than 5.0.2195.6972" negate="false" test_ref="oval:org.mitre.oval:tst:274"/>
          <criterion comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:273"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:592" version="1" class="vulnerability">
      <metadata>
        <title>rwho daemon Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1351" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1351"/>
        <description>Unknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 OR Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed">
            <criteria operator="OR" comment="Solaris 7 or 8 installed">
              <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
              <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            </criteria>
            <criteria operator="AND" comment="Solaris 9 and Remote Network Server Commands (SUNWrcmds) installed">
              <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
              <criterion comment="Remote Network Server Commands - Usr (SUNWrcmds) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2525"/>
            </criteria>
          </criteria>
          <criterion comment="Patch 118239-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2524"/>
          <criterion comment="Patch 116984-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2523"/>
          <criterion comment="Patch 117455-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2522"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.rwhod is running" negate="false" test_ref="oval:org.mitre.oval:tst:2521"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:591" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:51:00.000-04:00" comment="modified wft-12 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="the version of shtml.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2708"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (WinNT)" negate="false" test_ref="oval:org.mitre.oval:tst:2526"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:734" version="2">
      <metadata>
        <title>Microsoft Publisher 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Publisher 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.736-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.910-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Publisher 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:140"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:590" version="2">
      <metadata>
        <title>Microsoft Publisher Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Publisher</product>
        </affected>
        <reference ref_id="CVE-2006-0001" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0001" source="CVE"/>
        <description>Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <modified date="2006-09-25T03:45:32" comment="Modified obj:94 (used by tst:29, tst:36, and tst:168) to reference var:297 instead of var:231.  New version uses 'App Path' regkey for mspub.exe, instead of leveraging regkey for excel.exe.  Thanks to Anna Min of BigFix for reporting the issue.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-10-10T20:40:00.262-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:49.341-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Publisher 2000" operator="AND">
          <extend_definition comment="Microsoft Publisher 2000 is installed" definition_ref="oval:org.mitre.oval:def:427"/>
          <criterion comment="the version of mspub.exe is less than 9.0.0.8930" test_ref="oval:org.mitre.oval:tst:36"/>
        </criteria>
        <criteria comment="Publisher 2002" operator="AND">
          <extend_definition comment="Microsoft Publisher 2002 is installed" definition_ref="oval:org.mitre.oval:def:734"/>
          <criterion comment="the version of mspub.exe is less than 10.0.6815.0" test_ref="oval:org.mitre.oval:tst:168"/>
        </criteria>
        <criteria comment="Publisher 2003" operator="AND">
          <extend_definition comment="Microsoft Publisher 2003 is installed" definition_ref="oval:org.mitre.oval:def:239"/>
          <criterion comment="the version of mspub.exe is less than 11.0.8103.0" test_ref="oval:org.mitre.oval:tst:29"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:59" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Windows RPC Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1561"/>
        <description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" negate="false" test_ref="oval:org.mitre.oval:tst:3002"/>
        <criterion comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3001"/>
        <criterion comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3000"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:588" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false" test_ref="oval:org.mitre.oval:tst:2686"/>
          <criterion comment="the patch q824145 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2685"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:587" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (64-bit Server 2003 and XP Version 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003">
            <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
              <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.274" negate="false" test_ref="oval:org.mitre.oval:tst:2527"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2657"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:584" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla IDN heap overrun using soft-hyphens</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:582" version="1" class="vulnerability">
      <metadata>
        <title>MSJava Applet CODEBASE File Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Virtual Machine (VM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1258" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1258"/>
        <description>Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msjava.dll is less than 5.0.3809.0" negate="false" test_ref="oval:org.mitre.oval:tst:2536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:581" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="cdosys.dll is less than 6.5.6756.0" negate="false" test_ref="oval:org.mitre.oval:tst:2537"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:58" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS HTTP Redirect Error Message Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0075"/>
        <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:578" version="2">
      <metadata>
        <title>Microsoft Word Malformed Stack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference ref_id="CVE-2006-4534" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4534" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names including Trojan.Mdropper.Q, Mofei, and Femo.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:48.722-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:59.701-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8951" test_ref="oval:org.mitre.oval:tst:57"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6818.0" test_ref="oval:org.mitre.oval:tst:107"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8106.0" test_ref="oval:org.mitre.oval:tst:151"/>
        </criteria>
        <criteria comment="Word Viewer" operator="AND">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of wordview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:28"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:577" version="2">
      <metadata>
        <title>Source Element Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3639" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3639" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, aka "Source Element Cross-Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:31.779-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:45.074-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:576" version="1" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:575" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Workstation Service Logging Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Windows Workstation Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0812"/>
        <description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of wkssvc.dll is less than 5.00.2195.6862" negate="false" test_ref="oval:org.mitre.oval:tst:2541"/>
          <criterion comment="the patch q828748 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2540"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the workstation service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5740" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T02:20:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:31.382-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:573" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (32-bit XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.2900.2620" negate="false" test_ref="oval:org.mitre.oval:tst:2543"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2542"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:572" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail BO in Prescan Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="sendmail version is less than 8.12.8-5.90" negate="false" test_ref="oval:org.mitre.oval:tst:2549"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="AND" comment="sendmail is Set-UID">
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2548"/>
              <criteria operator="OR" comment="sendmail is Set-UID">
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2547"/>
                <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="sendmail is Set-GID">
              <criterion comment="sendmail is Set-GID" negate="false" test_ref="oval:org.mitre.oval:tst:2545"/>
              <criterion comment="sendmail is Set-UID" negate="false" test_ref="oval:org.mitre.oval:tst:2546"/>
            </criteria>
            <criterion comment="sendmail listening" negate="false" test_ref="oval:org.mitre.oval:tst:2544"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:570" version="2">
      <metadata>
        <title>Excel Malformed DATETIME Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-2387" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2387" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, Excel Viewer 2003, and Microsoft Works Suite 2004 through 2006 allows user-assisted attackers to execute arbitrary code via a crafted DATETIME record in an XLS file, a different vulnerability than CVE-2006-3867 and CVE-2006-3875.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:48.120-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:58.954-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:35"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6816.0" test_ref="oval:org.mitre.oval:tst:173"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8105.0" test_ref="oval:org.mitre.oval:tst:26"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:27"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:57" version="1" class="vulnerability">
      <metadata>
        <title>Improper Cross Domain Security Validation with ShowHelp Functionality</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1328"/>
        <description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Validation with ShowHelp functionality."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3003"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:569" version="1" class="vulnerability">
      <metadata>
        <title>Symlink Attack Vulnerability in semi/wemi MIME Libraries</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>semi MIME library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0440" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0440"/>
        <description>The (1) semi MIME library 1.14.5 and earlier, and (2) wemi 1.14.0 and possibly other versions, allows local users to overwrite arbitrary files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criteria operator="OR" comment="Vulnerable Config">
            <criterion comment="wl version is less than 2.10.1-1.1" negate="false" test_ref="oval:org.mitre.oval:tst:2557"/>
            <criterion comment="wl-xemacs version is less than 2.10.1-1.1" negate="false" test_ref="oval:org.mitre.oval:tst:2556"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="Vulnerable Config">
            <criteria operator="OR" comment="/usr/bin/emacs is executable">
              <criterion comment="/usr/bin/emacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2555"/>
              <criterion comment="/usr/bin/emacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2554"/>
              <criterion comment="/usr/bin/emacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2553"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/xemacs is executable">
              <criterion comment="/usr/bin/xemacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2552"/>
              <criterion comment="/usr/bin/xemacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2551"/>
              <criterion comment="/usr/bin/xemacs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2550"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:567" version="1" class="vulnerability">
      <metadata>
        <title>BO in Samba call_trans2open Function</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Samba, Samba-TNG</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201"/>
        <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 2.2.7a-8.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2559"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:566" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false" test_ref="oval:org.mitre.oval:tst:2686"/>
          <criterion comment="the patch q824145 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2685"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:564" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in Samba</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0196" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0196"/>
        <description>Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 2.2.7a-8.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2559"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2558"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5620" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 for 2003, SP3 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:56" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 rpc.yppasswdd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>rpc.yppasswdd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0779"/>
        <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.yppasswdd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3006"/>
          <criterion comment="Patch 111596-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3005"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.yppasswdd running" negate="false" test_ref="oval:org.mitre.oval:tst:3004"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5592" version="1" class="vulnerability">
      <metadata>
        <title>Windows (ME, NT, 2K), IE v5.5,SP2 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:49:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:557" version="2">
      <metadata>
        <title>Microsoft Excel Malformed SELECTION record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1301" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1301" source="CVE"/>
        <description>Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:30.912-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:44.263-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:556" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:555" version="1" class="vulnerability">
      <metadata>
        <title>Xsun Buffer Overflow via HOME Envvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0422" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0422"/>
        <description>Buffer overflow in Xsun in Solaris 8 and earlier allows local users to execute arbitrary commands via a long HOME environmental variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 installed">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        </criteria>
        <criterion comment="Patch 108376-25 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2562"/>
        <criterion comment="Patch 108652-30 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2561"/>
        <criterion comment="X Window System platform software (SUNWxwplt) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2560"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:554" version="1" class="vulnerability">
      <metadata>
        <title>Samba Arbitrary File Overwrite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0086" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0086"/>
        <description>The code for writing reg files in Samba before 2.2.8 allows local users to overwrite arbitrary files via a race condition involving chown.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="samba version is less than 2.2.7a-7.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2566"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:553" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft MDAC 2.6 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Compnents 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of odbcbcp.dll is less than 2000.80.747.0" negate="false" test_ref="oval:org.mitre.oval:tst:2564"/>
        <criterion comment="the version of sqlsrv32.dll is less than 2000.80.747.0" negate="false" test_ref="oval:org.mitre.oval:tst:2563"/>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5520" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.5, SP2 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:30.653-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:552" version="1" class="vulnerability">
      <metadata>
        <title>SMB/CIFS Packet Fragment Re-assembly BO</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>smbd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0085"/>
        <description>Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="samba version is less than 2.2.7a-7.9.0" negate="false" test_ref="oval:org.mitre.oval:tst:2566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2565"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:551" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Unchecked Buffer Permits Remote Code Execution or Privilege Elevation (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MSDTC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2119"/>
        <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:49.122-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5509" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server 2003 Routing Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>SMTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0840"/>
        <description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T10:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.3790.211" negate="false" test_ref="oval:org.mitre.oval:tst:558"/>
          <criterion comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" negate="true" test_ref="oval:org.mitre.oval:tst:557"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3054"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:550" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Shared Object Code Execution</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:55" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal NTLMSSP Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0159"/>
        <description>Heap-based buffer overflow in the NTLMSSP code for Ethereal 0.9.9 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="ethereal version is less than 0.9.11-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:3007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:549" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:548" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:545" version="2">
      <metadata>
        <title>Microsoft Excel Malformed COLINFO record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1304" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1304" source="CVE"/>
        <description>Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted COLINFO record, which triggers the overflow during a "data filling operation."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:30.285-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:43.952-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:544" version="1" class="vulnerability">
      <metadata>
        <title>Denial of Service Vulnerability in Postfix Parser Code</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Postfix</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0540" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0540"/>
        <description>The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="postfix version is less than 1.1.12-1" negate="false" test_ref="oval:org.mitre.oval:tst:2578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smtpd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:543" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-21T05:00:00.000-04:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2663"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:542" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Malformed PNG Image File Failure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1185"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:54" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal SOCKS String Format Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0081"/>
        <description>Format string vulnerability in packet-socks.c of the SOCKS dissector for Ethereal 0.8.7 through 0.9.9 allows remote attackers to execute arbitrary code via SOCKS packets containing format string specifiers.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="ethereal version is less than 0.9.11-0.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:3007"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:539" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Font Conversion Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Replaced all criteria. 1) Included XP64,Gold, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false" test_ref="oval:org.mitre.oval:tst:2570"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:537" version="2">
      <metadata>
        <title>Microsoft Excel Malformed File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-3059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3059" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors.  NOTE: this is a different vulnerability than CVE-2006-3086.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:30.080-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:43.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:535" version="2">
      <metadata>
        <title>Microsoft Indexing Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Indexing Service</product>
        </affected>
        <reference ref_id="CVE-2006-0032" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0032" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is injected into an error message whose charset is set to UTF-7.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.927-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.512-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Query.dll is less than 5.0.2195.7100" test_ref="oval:org.mitre.oval:tst:133"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Query.dll is less than 5.1.2600.1860" test_ref="oval:org.mitre.oval:tst:153"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Query.dll is less than 5.1.2600.2935" test_ref="oval:org.mitre.oval:tst:19"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Query.dll is less than 5.2.3790.2734" test_ref="oval:org.mitre.oval:tst:20"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Query.dll is less than 5.2.3790.552" test_ref="oval:org.mitre.oval:tst:21"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Query.dll is less than 5.2.3790.2734" test_ref="oval:org.mitre.oval:tst:20"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:534" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5329" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:35:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:532" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:51:00.000-04:00" comment="modified wft-93 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false" test_ref="oval:org.mitre.oval:tst:2580"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5316" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Install Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0216"/>
        <description>Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating a buffer length and leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:531" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5307" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Long Share Names Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0214"/>
        <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criteria operator="OR" comment="a vulnerable version of shell32.dll exists">
          <criteria operator="AND" comment="no service pack is installed and a vulnerable version of shell32.dll exists">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of shell32.dll is less than 6.0.2750.166" negate="false" test_ref="oval:org.mitre.oval:tst:275"/>
          </criteria>
          <criteria operator="AND" comment="service pack 1 is installed and a vulnerable version of shell32.dll exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of shell32.dll is less than 6.0.2800.1580" negate="false" test_ref="oval:org.mitre.oval:tst:381"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:530" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:53" version="2">
      <metadata>
        <title>ICMP Connection Reset Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790" source="CVE"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:47.544-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:58.212-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.1.2600.1886" test_ref="oval:org.mitre.oval:tst:68"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.1.2600.2975" test_ref="oval:org.mitre.oval:tst:86"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.2771" test_ref="oval:org.mitre.oval:tst:131"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.576" test_ref="oval:org.mitre.oval:tst:171"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.2771" test_ref="oval:org.mitre.oval:tst:131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:529" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5277" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed OVAL5277</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0569" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0569"/>
        <description>The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-18T11:46:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2004-10-20T02:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-22T09:29:00.000-04:00" comment="Changed CVE entry from 2003-0569 to 2004-0569">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2005-12-12T09:59:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of rpcrt4.dll is less than 4.0.1381.33578" negate="false" test_ref="oval:org.mitre.oval:tst:276"/>
        <criterion comment="Patch KB873350 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:529"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:527" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Function Pointer Drag and Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1027"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by using method caching (SaveRef) to access the window.moveBy method, which is otherwise inaccessible, as demonstrated by HijackClickV2, a different vulnerability than CVE-2003-0823, aka the "Function Pointer Drag and Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:526" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:54:00.000-04:00" comment="modified wft-95 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.118" negate="false" test_ref="oval:org.mitre.oval:tst:2572"/>
        <criterion comment="the patch q832894 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2571"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:525" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft MDAC 2.5 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Compnents 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="the version of odbcbcp.dll is less than 3.70.11.46" negate="false" test_ref="oval:org.mitre.oval:tst:2575"/>
        <criterion comment="the version of sqlsrv32.dll is less than 3.70.11.46" negate="false" test_ref="oval:org.mitre.oval:tst:2574"/>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:522" version="1" class="vulnerability">
      <metadata>
        <title>Postfix Bounce Scans Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Postfix</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0468" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0468"/>
        <description>Postfix 1.1.11 and earlier allows remote attackers to use Postfix to conduct "bounce scans" or DDos attacks of other hosts via an email address to the local host containing the target IP address and service name followed by a "!" string, which causes Postfix to attempt to use SMTP to communicate with the target on the associated port.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="postfix version is less than 1.1.12-1" negate="false" test_ref="oval:org.mitre.oval:tst:2578"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smtpd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2577"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:520" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:52" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Eye of GNOME (EOG) Packages Fix Format String Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>EOG</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0165"/>
        <description>Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="eog version is less than 2.2.0-2" negate="false" test_ref="oval:org.mitre.oval:tst:3011"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="eog is executable">
            <criterion comment="eog is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:3010"/>
            <criterion comment="eog is group-executable" negate="false" test_ref="oval:org.mitre.oval:tst:3009"/>
            <criterion comment="eog is owner-executable" negate="false" test_ref="oval:org.mitre.oval:tst:3008"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:519" version="1" class="vulnerability">
      <metadata>
        <title>Scob and Toofer Internet Explorer v6.0 Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549"/>
        <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-02T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:19:00.000-04:00" comment="modified wft-268 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2743.600" negate="false" test_ref="oval:org.mitre.oval:tst:2583"/>
          <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:517" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T11:00:00.000-04:00" comment="modified wft-266 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.191" negate="false" test_ref="oval:org.mitre.oval:tst:2800"/>
        <criterion comment="the patch kb867801 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2799"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5150" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP4 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:29.549-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:515" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5141" version="1" class="vulnerability">
      <metadata>
        <title>CDE libDtHelp Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0834" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0834"/>
        <description>Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="CDE Application Runtime or CDE Separable Help (any SUNWdtbas/SUNWdtbax/SUNWdthep) installed">
          <criterion comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" negate="false" test_ref="oval:org.mitre.oval:tst:459"/>
          <criterion comment="Separable help for CDE (SUNWdthep) installed" negate="false" test_ref="oval:org.mitre.oval:tst:280"/>
        </criteria>
        <criterion comment="Patch 107178-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:279"/>
        <criterion comment="Patch 108949-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:278"/>
        <criterion comment="Patch 116308-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:277"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:514" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.503-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:513" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:52:00.000-04:00" comment="modified wft-94 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1400" negate="false" test_ref="oval:org.mitre.oval:tst:2579"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:512" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:51:00.000-04:00" comment="modified wft-93 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2737.800" negate="false" test_ref="oval:org.mitre.oval:tst:2580"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:511" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4937.800" negate="false" test_ref="oval:org.mitre.oval:tst:2581"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:510" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:49:00.000-04:00" comment="modified wft-91 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3813.800" negate="false" test_ref="oval:org.mitre.oval:tst:2582"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:51" version="2">
      <metadata>
        <title>Microsoft Word Mail Merge Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference ref_id="CVE-2006-3651" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3651" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:46.772-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:57.326-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8951" test_ref="oval:org.mitre.oval:tst:57"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6818.0" test_ref="oval:org.mitre.oval:tst:107"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8106.0" test_ref="oval:org.mitre.oval:tst:151"/>
        </criteria>
        <criteria comment="Word Viewer" operator="AND">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of wordview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:28"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:509" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:21:00.000-04:00" comment="modified wft-279 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3819.300" negate="false" test_ref="oval:org.mitre.oval:tst:2793"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:508" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Zone Restrictions Bypass via XML Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0817" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0817"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5074" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (32-Bit) Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T05:10:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criteria operator="OR" comment="a vulnerable version of nddenb32.dll exists">
          <criteria operator="AND" comment="no service pack is installed and a vulnerable version of nddenb32.dll exists">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of nddenb32.dll is less than 5.1.2600.149" negate="false" test_ref="oval:org.mitre.oval:tst:282"/>
          </criteria>
          <criteria operator="AND" comment="Service Pack 1 is installed and a vulnerable version of nddenb32.dll exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of nddenb32.dll is less than 5.1.2600.1555" negate="false" test_ref="oval:org.mitre.oval:tst:443"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="a vulnerable version of netdde.exe exists">
          <criteria operator="AND" comment="no service pack is installed and a vulnerable version of netdde.exe exists">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of netdde.exe is less than 5.1.2600.158" negate="false" test_ref="oval:org.mitre.oval:tst:281"/>
          </criteria>
          <criteria operator="AND" comment="Service Pack 1 is installed and a vulnerable version of netdde.exe exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of netdde.exe is less than 5.1.2600.1567" negate="false" test_ref="oval:org.mitre.oval:tst:445"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5070" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT NNTP Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0574"/>
        <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:15:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="the version of nntpsvc.dll is less than 5.5.1877.79" negate="false" test_ref="oval:org.mitre.oval:tst:284"/>
          <criterion comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" negate="true" test_ref="oval:org.mitre.oval:tst:283"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:507" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:19:00.000-04:00" comment="modified wft-268 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2743.600" negate="false" test_ref="oval:org.mitre.oval:tst:2583"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:503" version="1" class="vulnerability">
      <metadata>
        <title>Integer Signedness Error in PINE</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>pine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0721" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0721"/>
        <description>Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pine version is less than 4.44-19.90.0" negate="false" test_ref="oval:org.mitre.oval:tst:2587"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/pine is executable">
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2586"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2585"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2584"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5021" version="1" class="vulnerability">
      <metadata>
        <title>Office on Windows Server 2003 WordPerfect Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0573"/>
        <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T12:21:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of nntpsvc.dll is less than 6.0.3790.206" negate="false" test_ref="oval:org.mitre.oval:tst:2759"/>
          <criterion comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2758"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:502" version="2">
      <metadata>
        <title>HTML Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3637" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3637" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:29.304-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:43.220-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:500" version="1" class="vulnerability">
      <metadata>
        <title>Default Permissions on RAS Administration Key</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Access Service (RAS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0045"/>
        <description>The default permissions for the RAS Administration key in Windows NT 4.0 allows local users to execute arbitrary commands by changing the value to point to a malicious DLL, aka one of the "Registry Permissions" vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-06-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="AND" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
            <criterion comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" negate="false" test_ref="oval:org.mitre.oval:tst:2896"/>
            <criterion comment="Windows NT 4.0 Security Roll-up Package" negate="true" test_ref="oval:org.mitre.oval:tst:3036"/>
          </criteria>
          <criteria operator="AND" comment="For Terminal Server">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" negate="false" test_ref="oval:org.mitre.oval:tst:2895"/>
          </criteria>
          <criterion comment="Patch Q265714 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2894"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RAS Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2996"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:50" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.0.3502.4856" negate="false" test_ref="oval:org.mitre.oval:tst:3012"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:5" version="2">
      <metadata>
        <title>CSS Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3451" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3451" source="CVE"/>
        <description>Microsoft Internet Explorer 5 SP4 and 6 do not properly garbage collect when "multiple imports are used on a styleSheets collection" to construct a chain of Cascading Style Sheets (CSS), which allows remote attackers to execute arbitrary code via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:28.875-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:42.731-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:499" version="1" class="vulnerability">
      <metadata>
        <title>PINE Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>pine</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0720"/>
        <description>Buffer overflow in PINE before 4.58 allows remote attackers to execute arbitrary code via a malformed message/external-body MIME type.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="pine version is less than 4.44-19.90.0" negate="false" test_ref="oval:org.mitre.oval:tst:2587"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/pine is executable">
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2586"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2585"/>
            <criterion comment="/usr/bin/pine is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2584"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4988" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Message Queuing Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Message Queuing</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0059"/>
        <description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of mqrt.dll is less than 5.0.0.799" negate="false" test_ref="oval:org.mitre.oval:tst:285"/>
        <criterion comment="the patch KB892944 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:328"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4987" version="1" class="vulnerability">
      <metadata>
        <title>.NET Framework v1.0 Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MDAC 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0847"/>
        <description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Is the .NET Framework 1.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:292"/>
        <criteria operator="OR" comment="A vulnerable version of .NET Framework v1.0 is installed.">
          <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.0 (SP 2) is installed.">
            <criterion comment="Is the KB886905 patch installed for .NET Framework v1.0 sp 2?" negate="true" test_ref="oval:org.mitre.oval:tst:291"/>
            <criterion comment="the version of System.web.dll is less than 1.0.3705.556" negate="false" test_ref="oval:org.mitre.oval:tst:290"/>
            <criterion comment="Is Service Pack 2 for .NET Framework 1.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:289"/>
          </criteria>
          <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.0 (SP 3) is installed.">
            <criterion comment="Is Service Pack 3 for .NET Framework 1.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:288"/>
            <criterion comment="the version of System.web.dll is less than 1.0.3705.6021" negate="false" test_ref="oval:org.mitre.oval:tst:287"/>
            <criterion comment="Is the KB886906 patch installed for .NET Framework v1.0 sp 3?" negate="true" test_ref="oval:org.mitre.oval:tst:286"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4985" version="1" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE5.01,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false" test_ref="oval:org.mitre.oval:tst:567"/>
          <criterion comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4978" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Object Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0688"/>
        <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:58.970-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
          <criterion comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false" test_ref="oval:org.mitre.oval:tst:2354"/>
          <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="The SynAttackProtect parameter is set to 2" negate="false" test_ref="oval:org.mitre.oval:tst:293"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:497" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.301-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3750"/>
        <criterion comment="SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3341"/>
        <criterion comment="64-bit version" negate="true" test_ref="oval:org.mitre.oval:tst:3257"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.1.2600.2710" negate="false" test_ref="oval:org.mitre.oval:tst:3964"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:496" version="2">
      <metadata>
        <title>Object Packager Dialogue Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-4692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4692" source="CVE"/>
        <description>Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) character in the filename of the Command Line property, followed by a valid file extension, which causes the command before the slash to be executed, aka "Object Packager Dialogue Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:46.125-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:56.442-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Shdocvw.dll is less than 6.0.2800.1892" test_ref="oval:org.mitre.oval:tst:43"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Shdocvw.dll is less than 6.0.2900.2987" test_ref="oval:org.mitre.oval:tst:48"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Shdocvw.dll is less than 6.0.3790.2783" test_ref="oval:org.mitre.oval:tst:47"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Shdocvw.dll is less than 6.0.3790.588" test_ref="oval:org.mitre.oval:tst:52"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Shdocvw.dll is less than 6.0.3790.2783" test_ref="oval:org.mitre.oval:tst:47"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:495" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Encoded Characters Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1186"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4947" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:494" version="1" class="vulnerability">
      <metadata>
        <title>MS Windows RPC DCOM DoS-based Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0605"/>
        <description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4936" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos 5 KDC ASN.1 Error Handling Double-free Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0642"/>
        <description>Double-free vulnerabilities in the error handling code for ASN.1 decoders in the (1) Key Distribution Center (KDC) library and (2) client library for MIT Kerberos 5 (krb5) 1.3.4 and earlier may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed kerberos unknown test to solaris file contents test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:616"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4927" version="1" class="vulnerability">
      <metadata>
        <title>MSN Messenger GIF Size Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0562"/>
        <description>GIF file validation error in MSN Messenger 6.2 allows remote attackers in a user's contact list to execute arbitrary code via a GIF image with an improper height and width.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-11-24T12:00:00.000-04:00" comment="Added wrt-620 to see if MSN Messenger 6.2 is installed.  Changed wrt-431 to check 'DisplayVersion' rather than 'MSN Messenger 6.2'.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Added wrt-431.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MSN Messenger 6.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2520"/>
        <criterion comment="MSN Messenger 6.2.0208 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:294"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:492" version="2">
      <metadata>
        <title>Buffer Overrun in Server Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3439" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3439" source="CVE"/>
        <description>Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:28.555-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:42.347-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of netapi32.dll is less than 5.0.2195.7105" test_ref="oval:org.mitre.oval:tst:13"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of netapi32.dll is less than 5.1.2600.1874" test_ref="oval:org.mitre.oval:tst:147"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of netapi32.dll is less than 5.1.2600.2952" test_ref="oval:org.mitre.oval:tst:101"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of netapi32.dll is less than 5.2.3790.2747" test_ref="oval:org.mitre.oval:tst:126"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of netapi32.dll is less than 5.2.3790.559" test_ref="oval:org.mitre.oval:tst:176"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of netapi32.dll is less than 5.2.3790.2747" test_ref="oval:org.mitre.oval:tst:126"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:491" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:490" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Improper URL Canonicalization Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1025"/>
        <description>Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before an @ sign in the user@domain portion of the URL, which hides the rest of the URL, including the real site, in the address bar, aka the "Improper URL Canonicalization Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-02-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:50:00.000-04:00" comment="modified wft-90 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3526.800" negate="false" test_ref="oval:org.mitre.oval:tst:2589"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:49" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01 Improper Cross Domain Security Validation with Dialog Box</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1326"/>
        <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" negate="false" test_ref="oval:org.mitre.oval:tst:3014"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3013"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4893" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Windows Kernel Local Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0211"/>
        <description>The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:31:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-10-13T11:43:00.000-04:00" comment="changed OS">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of win32k.sys is less than 5.2.3790.198" negate="false" test_ref="oval:org.mitre.oval:tst:738"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criteria operator="OR" comment="Windows 2003 Server or Windows XP 64-bit">
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:489" version="1" class="vulnerability">
      <metadata>
        <title>Unchecked Buffer in SQLXML ISAPI Extension (MDAC 2.7)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0186"/>
        <description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <modified date="2004-09-16T12:00:00.000-04:00" comment="Input of initial submission.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-09-22T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-492 - wft-492 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 installed" negate="false" test_ref="oval:org.mitre.oval:tst:2591"/>
        <criterion comment="MDAC 2.7 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2590"/>
        <criterion comment="the version of sqlisapi.dll is less than 2000.80.309.0" negate="false" test_ref="oval:org.mitre.oval:tst:2594"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.760.0" negate="false" test_ref="oval:org.mitre.oval:tst:2593"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4874" version="1" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE5.01,SP3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1083"/>
          <criterion comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4864" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
            <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
            <criterion comment="the patch kb834707(wildcard*) is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:977"/>
          </criteria>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4863" version="1" class="vulnerability">
      <metadata>
        <title>Apache Mod_Proxy Remote Negative Content-Length Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492"/>
        <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:12:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:16:00.000-04:00" comment="Changed apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:20:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:486" version="2">
      <metadata>
        <title>Excel Malformed COLINFO Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3875" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted COLINFO record in an XLS file, a different vulnerability than CVE-2006-2387 and CVE-2006-3867.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:45.018-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:55.032-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:35"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6816.0" test_ref="oval:org.mitre.oval:tst:173"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8105.0" test_ref="oval:org.mitre.oval:tst:26"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:27"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4859" version="1" class="vulnerability">
      <metadata>
        <title>Proxy Server Reverse DNS Lookup Results Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Proxy Server 2.0 SP1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0892"/>
        <description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-01T12:00:00.000-04:00" comment="modified wft-7 - Corrected path">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="modified wft-7 - corrected object path">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Proxy Server 2.0 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:297"/>
        <criterion comment="the version of w3proxy.dll is less than 2.0.390.16" negate="false" test_ref="oval:org.mitre.oval:tst:296"/>
        <criterion comment="the patch KB888258 for Proxy Server 2.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:295"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:485" version="1" class="vulnerability">
      <metadata>
        <title>PH Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>php</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0442"/>
        <description>Cross-site scripting (XSS) vulnerability in the transparent SID support capability for PHP before 4.3.2 (session.use_trans_sid) allows remote attackers to insert arbitrary script via the PHPSESSID parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="php version is less than 4.2.2-17.2" negate="false" test_ref="oval:org.mitre.oval:tst:2592"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4846" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT DHCP Request Code Execution Vulnerability (Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>DHCP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0900" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0900"/>
        <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the "DHCP Request Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the patch KB885249 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:561"/>
        <criterion comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" negate="false" test_ref="oval:org.mitre.oval:tst:335"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:484" version="1" class="vulnerability">
      <metadata>
        <title>Unchecked Buffer in SQLXML ISAPI Extension (MDAC 2.6)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0186"/>
        <description>Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <modified date="2004-09-16T12:00:00.000-04:00" comment="filling out initial submission.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <modified date="2004-09-16T10:31:00.000-04:00" comment="Added service pack 3 test">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-09-22T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-492 - wft-492 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="MDAC 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of sqlisapi.dll is less than 2000.80.309.0" negate="false" test_ref="oval:org.mitre.oval:tst:2594"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.760.0" negate="false" test_ref="oval:org.mitre.oval:tst:2593"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4834" version="1" class="vulnerability">
      <metadata>
        <title>LDAP RBAC Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>LDAP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1353"/>
        <description>Unknown vulnerability in LDAP on Sun Solaris 8 and 9, when using Role Based Access Control (RBAC), allows local users to execute certain commands with additional privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 108993-38 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:300"/>
          <criterion comment="Patch 112960-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:299"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/nsswitch.conf configured to use LDAP with RBAC" negate="false" test_ref="oval:org.mitre.oval:tst:298"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4832" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Object Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0550"/>
        <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4831" version="2" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows NT 4.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:58.694-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of wins.exe is less than 4.0.1381.7329" negate="false" test_ref="oval:org.mitre.oval:tst:301"/>
          <criterion comment="the patch KB870763 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:865"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:483" version="1" class="vulnerability">
      <metadata>
        <title>IIS Server Side Include Web Pages Buffer Overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0224" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0224"/>
        <description>Buffer overflow in ssinc.dll for Microsoft Internet Information Services (IIS) 5.0 allows local users to execute arbitrary code via a web page with a Server Side Include (SSI) directive with a long filename, aka "Server Side Include Web Pages Buffer Overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" negate="false" test_ref="oval:org.mitre.oval:tst:2595"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:482" version="2">
      <metadata>
        <title>Spoofed Connection Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2005-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0688" source="CVE"/>
        <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:44.346-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:54.264-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.1.2600.1886" test_ref="oval:org.mitre.oval:tst:68"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.1.2600.2975" test_ref="oval:org.mitre.oval:tst:86"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.2771" test_ref="oval:org.mitre.oval:tst:131"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.576" test_ref="oval:org.mitre.oval:tst:171"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.2771" test_ref="oval:org.mitre.oval:tst:131"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:481" version="2">
      <metadata>
        <title>Excel Handling of Lotus 1-2-3 File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-3867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3867" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, 2003, 2004 for Mac, v.X for Mac, and Excel Viewer 2003 allows user-assisted attackers to execute arbitrary code via a crafted Lotus 1-2-3 file, a different vulnerability than CVE-2006-2387 and CVE-2006-3875.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:43.590-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:53.475-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:35"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6816.0" test_ref="oval:org.mitre.oval:tst:173"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8105.0" test_ref="oval:org.mitre.oval:tst:26"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:27"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4804" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Blind Connection Reset Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:58.522-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false" test_ref="oval:org.mitre.oval:tst:2354"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:48" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 AdminTool Media Installation Path Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Admintool</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0088"/>
        <description>Buffer overflow in admintool in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long media installation path.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-06-13T02:02:00.000-04:00" comment="modified uft-15 - admintool is either /bin/admintool or /usr/bin/admintool (or both).  Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search.  Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:20:00.000-04:00" comment="modified upt-845 - admintool is either /bin/admintool or /usr/bin/admintool (or both). Regular expression had been ^.*/bin/admintool$, which could cause arbitrary-depth search. Changed to ^(/usr)?/bin/admintool$, which bounds the search properly.  Also modified to test for both SUID and OEXEC bits, so a second test is not needed.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-06-13T02:22:00.000-04:00" comment="Removed compound test for &quot;admintool SUID and executable&quot; because new version of upt-845 does both.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:28.137-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File admintool exists" negate="false" test_ref="oval:org.mitre.oval:tst:3017"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File admintool SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3016"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4797" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Font Buffer Overflow (SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0060"/>
        <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
        <criteria operator="AND" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634">
          <criteria operator="OR" comment="Windows No Service Pack or Service Pack 1">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" negate="false" test_ref="oval:org.mitre.oval:tst:413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4791" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Large Window Size TCP RST Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230"/>
        <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:58.351-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:479" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-21T05:00:00.000-04:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2663"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4786" version="2" class="vulnerability">
      <metadata>
        <title>License Logging Service Vulnerability (Windows NT)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>MDAC 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0050"/>
        <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:58.184-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb885834 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2477"/>
          <criterion comment="the version of Llssrv.exe is less than 4.0.1381.7345" negate="false" test_ref="oval:org.mitre.oval:tst:302"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="license logging service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:478" version="1" class="vulnerability">
      <metadata>
        <title>MS Internet Security and Acceleration Server H.323 Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Security and Acceleration Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0819" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0819"/>
        <description>Buffer overflow in the H.323 filter of Microsoft Internet Security and Acceleration Server 2000 allows remote attackers to execute arbitrary code in the Microsoft Firewall Service via certain H.323 traffic, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="ISA Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2935"/>
          <criterion comment="the version of h32fltr.dll is less than 3.0.1200.291" negate="false" test_ref="oval:org.mitre.oval:tst:2599"/>
          <criterion comment="the patch q816458 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2598"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="H.323 filter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2597"/>
          <criterion comment="Microsoft Firewall Service is not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:2596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4767" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 IIS WebDAV Message Handler Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0718"/>
        <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T12:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
        <criterion comment="the version of httpext.dll is less than 6.0.3790.212" negate="false" test_ref="oval:org.mitre.oval:tst:303"/>
        <criterion comment="the patch KB824151 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:984"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4762" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Terminal Server VDM Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0208"/>
        <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T12:02:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of gdi32.dll is less than 4.0.1381.33566" negate="false" test_ref="oval:org.mitre.oval:tst:304"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:476" version="2">
      <metadata>
        <title>PowerPoint Malformed Object Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference ref_id="CVE-2006-3435" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3435" source="CVE"/>
        <description>PowerPoint in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac does not properly parse the slide notes field in a document, which allows remote user-assisted attackers to execute arbitrary code via crafted data in this field, which triggers an erroneous object pointer calculation that uses data from within the document. NOTE: this issue is different than other PowerPoint vulnerabilities including CVE-2006-4694.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:43.079-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:52.814-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="PowerPoint 2003" operator="AND">
        <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
        <criterion comment="the version of PowerPnt.exe is less than 11.0.8110.0" test_ref="oval:org.mitre.oval:tst:184"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4758" version="1" class="vulnerability">
      <metadata>
        <title>IE AbusiveParent Vulnerability (64-bit Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
        <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows Server 2003 64-Bit Edition or Windows XP 64-Bit Edition Version 2003">
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
        <criterion comment="the version of wdhtmled.ocx is less than 6.1.0.9231" negate="false" test_ref="oval:org.mitre.oval:tst:305"/>
        <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4756" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firebird, Firefox Frame Injection Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0718"/>
        <description>The (1) Mozilla 1.6, (2) Firebird 0.7, (3) Firefox 0.8, and (4) Netscape 7.1 web browsers do not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4749" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed: Duplicate of OVAL3882</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mswrd6.wpc is less than 10.0.803.2" negate="false" test_ref="oval:org.mitre.oval:tst:2422"/>
        <criterion comment="the patch kb885836 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1104"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4741" version="1" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-200 - access DLL via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of hypertrm.dll is less than 5.0.2195.7000" negate="false" test_ref="oval:org.mitre.oval:tst:307"/>
          <criterion comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed" negate="true" test_ref="oval:org.mitre.oval:tst:306"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:474" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:48.172-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.755-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3381"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.0.2195.7057" negate="false" test_ref="oval:org.mitre.oval:tst:3723"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4728" version="2" class="vulnerability">
      <metadata>
        <title>SunRPC xdr_array Function Integer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Sun RPC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:27.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>Specific applications using this library are not tested for because Suns advisory only provides a sample of known vulnerable applications and states that they are still investigating.</note>
      </notes>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="AND" comment="Patches 106942-22 and 108451-06 or later installed" negate="true">
          <criterion comment="Patch 106942-22 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3026"/>
          <criterion comment="Patch 108451-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:310"/>
        </criteria>
        <criteria operator="AND" comment="Patches 108827-30 and 108901-06" negate="true">
          <criterion comment="Patch 108827-30 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3138"/>
          <criterion comment="Patch 108901-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3137"/>
        </criteria>
        <criteria operator="AND" comment="Patches 113319-01 and 112233-02 or later installed" negate="true">
          <criterion comment="Patch 113319-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:309"/>
          <criterion comment="Patch 112233-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:308"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4726" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003/64-bit XP Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb890047.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.241" negate="false" test_ref="oval:org.mitre.oval:tst:311"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:472" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-21T05:00:00.000-04:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2663"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4710" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T10:01:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 5.0.3900.7032" negate="false" test_ref="oval:org.mitre.oval:tst:313"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:312"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:471" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01 Encoded Characters Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1186"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" negate="false" test_ref="oval:org.mitre.oval:tst:2606"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4706" version="1" class="vulnerability">
      <metadata>
        <title>Help and Support Center PCHealth System Buffer Overflow (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0711"/>
        <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows Server 2003 or Windows 64-bit Edition is installed">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of itircl.dll is less than 5.2.3790.80" negate="false" test_ref="oval:org.mitre.oval:tst:2792"/>
        <criterion comment="Patch KB825119 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2791"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4702" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Similar Method Name Redirection Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0727"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T07:27:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:470" version="1" class="vulnerability">
      <metadata>
        <title>CGI.pm Cross-site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>CGI.pm</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0615"/>
        <description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="perl-CGI version is less than 2.81-88.3" negate="false" test_ref="oval:org.mitre.oval:tst:2607"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:47" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 whodo Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>whodo</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1076"/>
        <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File whodo exists" negate="false" test_ref="oval:org.mitre.oval:tst:3043"/>
          <criterion comment="Patch 111826-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3018"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File whodo SUID and executable">
            <criterion comment="File whodo SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3041"/>
            <criterion comment="File whodo SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3040"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:469" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in PAM SMB Module</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>pam_smb</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0686"/>
        <description>Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="pam_smb version is less than 1.1.6-9.9" negate="false" test_ref="oval:org.mitre.oval:tst:2608"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:468" version="1" class="vulnerability">
      <metadata>
        <title>ISA Server NetBIOS Packet Filter Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>ISA Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1216" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1216"/>
        <description>Microsoft ISA Server 2000 allows remote attackers to connect to services utilizing the NetBIOS protocol via a NetBIOS connection with an ISA Server that uses the NetBIOS (all) predefined packet filter.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-06-29T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wft-81 - Removed extra trailing \\ on registry component.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="ISA Server 2000 SP2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2611"/>
        <criterion comment="the version of w3proxy.exe is less than 3.0.1200.430" negate="false" test_ref="oval:org.mitre.oval:tst:2610"/>
        <criterion comment="the patch KB899753 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4674" version="1" class="vulnerability">
      <metadata>
        <title>IE6 (for Server 2003) Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:44:00.000-04:00" comment="modified wft-594 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.279" negate="false" test_ref="oval:org.mitre.oval:tst:515"/>
          <criterion comment="the patch kb890923 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:514"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4671" version="1" class="vulnerability">
      <metadata>
        <title>LoadImage Cursor and Icon Format Handling Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Cursor and Icon Formatting</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1049"/>
        <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.0.2195.7017" negate="false" test_ref="oval:org.mitre.oval:tst:446"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4670" version="1" class="vulnerability">
      <metadata>
        <title>Apache Mod_Access Access Control Rule Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993"/>
        <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:16:00.000-04:00" comment="Changes apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:19:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:467" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Unknown Vector SMB Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Small Business Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1206"/>
        <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the patch KB896422 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2743"/>
        <criterion comment="the version of srv.sys is less than 5.0.2195.7044" negate="false" test_ref="oval:org.mitre.oval:tst:2612"/>
        <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4661" version="1" class="vulnerability">
      <metadata>
        <title>MIT Kerberos 5 Multiple Double-Free Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0772"/>
        <description>Double-free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T03:18:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:616"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Kerberos Key Distribution Center (krb5kdc) running" negate="false" test_ref="oval:org.mitre.oval:tst:314"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:466" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL No RSA Blinding Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0147"/>
        <description>OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="affected version of SSL and TLS components for OpenSSL">
          <criterion comment="openssl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2618"/>
          <criterion comment="openssl-devel version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2617"/>
          <criterion comment="openssl-perl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2616"/>
          <criterion comment="openssl096 version is less than 0.9.6-17" negate="false" test_ref="oval:org.mitre.oval:tst:2615"/>
          <criterion comment="openssl096b version is less than 0.9.6b-6" negate="false" test_ref="oval:org.mitre.oval:tst:2614"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:464" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.997-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.567-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 118822-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3505"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101658 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 118844-28 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3302"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:463" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 HTML Help Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1208"/>
        <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of hh.exe is less than 5.2.3790.309" negate="false" test_ref="oval:org.mitre.oval:tst:2613"/>
        <criterion comment="the patch kb896358 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2668"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4629" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Netscape SOAPParameter Integer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0722" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0722"/>
        <description>Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:462" version="2">
      <metadata>
        <title>FTP Server Command Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2004-1166" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1166" source="CVE"/>
        <description>Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:27.314-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.334-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:461" version="1" class="vulnerability">
      <metadata>
        <title>Klima-Pokorny-Rosa Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0131" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0131"/>
        <description>The SSL and TLS components for OpenSSL 0.9.6i and earlier, 0.9.7, and 0.9.7a allow remote attackers to perform an unauthorized RSA private key operation via a modified Bleichenbacher attack that uses a large number of SSL or TLS connections using PKCS #1 v1.5 padding that cause OpenSSL to leak information regarding the relationship between ciphertext and the associated plaintext, aka the "Klima-Pokorny-Rosa attack."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <modified date="2004-05-11T12:00:00.000-04:00" comment="Added cmp-914 which uses an or to combine the 5 version tests. Previously the tests had been combined with an and.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="affected version of SSL and TLS components for OpenSSL">
          <criterion comment="openssl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2618"/>
          <criterion comment="openssl-devel version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2617"/>
          <criterion comment="openssl-perl version is less than 0.9.7a-5" negate="false" test_ref="oval:org.mitre.oval:tst:2616"/>
          <criterion comment="openssl096 version is less than 0.9.6-17" negate="false" test_ref="oval:org.mitre.oval:tst:2615"/>
          <criterion comment="openssl096b version is less than 0.9.6b-6" negate="false" test_ref="oval:org.mitre.oval:tst:2614"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:46" version="1" class="vulnerability">
      <metadata>
        <title>IIS Help File Search Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0074" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0074"/>
        <description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4593" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Access Requests Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0061"/>
        <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4592" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (32-Bit) Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T04:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criterion comment="the version of nddenb32.dll is less than 5.2.3790.173" negate="false" test_ref="oval:org.mitre.oval:tst:316"/>
        <criterion comment="the version of netdde.exe is less than 5.2.3790.184" negate="false" test_ref="oval:org.mitre.oval:tst:315"/>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:459" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false" test_ref="oval:org.mitre.oval:tst:2686"/>
          <criterion comment="the patch q824145 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2685"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4576" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Font Conversion Vulnerability (NT Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 4.0.1381.33598" negate="false" test_ref="oval:org.mitre.oval:tst:955"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4574" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL ASN.1 Inputs Character Tracking Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Cluster</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0544" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0544"/>
        <description>OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:10:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113505-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:511"/>
          <criterion comment="Patch 113508-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:510"/>
          <criterion comment="Patch 115054-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:509"/>
          <criterion comment="Patch 115055-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:508"/>
          <criterion comment="SunCluster Component SUNWscvw installed" negate="false" test_ref="oval:org.mitre.oval:tst:507"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running with SunPlex Manager config" negate="false" test_ref="oval:org.mitre.oval:tst:506"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:457" version="2">
      <metadata>
        <title>PGM Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>MSMQ Service</product>
        </affected>
        <reference ref_id="CVE-2006-3442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3442" source="CVE"/>
        <description>Unspecified vulnerability in Pragmatic General Multicast (PGM) in Microsoft Windows XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted multicast message.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.860-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.397-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Rmcast.sys is less than 5.1.2600.1873" test_ref="oval:org.mitre.oval:tst:188"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Rmcast.sys is less than 5.1.2600.2951" test_ref="oval:org.mitre.oval:tst:172"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4561" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Code Execution DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0669" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0669"/>
        <description>Unknown vulnerability in Solaris 2.6 through 9 causes a denial of service (system panic) via "a rare race condition" or an attack by local users.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 106541-25 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:319"/>
        <criterion comment="Patch 108528-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:318"/>
        <criterion comment="Patch 112233-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:317"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4549" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 IP Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0048"/>
        <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:57.656-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false" test_ref="oval:org.mitre.oval:tst:2354"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:453" version="2">
      <metadata>
        <title>PowerPoint Malformed Data Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference ref_id="CVE-2006-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3876" source="CVE"/>
        <description>Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via a crafted Data record in a PPT file, a different vulnerability than CVE-2006-3435 and CVE-2006-4694.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:41.801-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:51.161-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="PowerPoint 2000" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of powerpnt.exe is less than 9.0.0.8952" test_ref="oval:org.mitre.oval:tst:165"/>
        </criteria>
        <criteria comment="PowerPoint 2002" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of powerpnt.exe is less than 10.0.6819.0" test_ref="oval:org.mitre.oval:tst:50"/>
        </criteria>
        <criteria comment="PowerPoint 2003" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8110.0" test_ref="oval:org.mitre.oval:tst:184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:452" version="1" class="vulnerability">
      <metadata>
        <title>Mutliple Buffer Management Errors in OpenSSH</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0695" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0695"/>
        <description>Multiple "buffer management errors" in OpenSSH before 3.7.1 may allow attackers to cause a denial of service or execute arbitrary code using (1) buffer_init in buffer.c, (2) buffer_free in buffer.c, or (3) a separate function in channels.c, a different vulnerability than CVE-2003-0693.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2627"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:451" version="1" class="vulnerability">
      <metadata>
        <title>Windows ListView Shatter Message Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Utilities Manager/Windows Messaging</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0350" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0350"/>
        <description>The control for listing accessibility options in the Accessibility Utility Manager on Windows 2000 (ListView) does not properly handle Windows messages, which allows local users to execute arbitrary code via a "Shatter" style message to the Utility Manager that references a user-controlled callback function.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of sp3res.dll is less than 5.0.2195.6713" negate="false" test_ref="oval:org.mitre.oval:tst:2621"/>
        <criterion comment="the version of umandlg.dll is less than 1.0.0.3" negate="false" test_ref="oval:org.mitre.oval:tst:2620"/>
        <criterion comment="Patch KB822679 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2619"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4508" version="1" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-263 - access DLL via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of hypertrm.dll is less than 4.0.1381.842" negate="false" test_ref="oval:org.mitre.oval:tst:320"/>
          <criterion comment="the patch NT Server kb873339 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:369"/>
          <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:450" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (32-bit XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.1.2600.2525" negate="false" test_ref="oval:org.mitre.oval:tst:2623"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:45" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT HTR ISAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0071"/>
        <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ism.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4499" version="1" class="vulnerability">
      <metadata>
        <title>OLE Component Input Validation Vulnerability (Windows XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>unknown</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0044"/>
        <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.1.2600.1619" negate="false" test_ref="oval:org.mitre.oval:tst:472"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4493" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2003 (64-Bit) Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="a vulnerable version of grpconv.exe exists">
          <criterion comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" negate="false" test_ref="oval:org.mitre.oval:tst:339"/>
          <criterion comment="the version of grpconv.exe (syswow64) is less than 5.2.3790.205" negate="false" test_ref="oval:org.mitre.oval:tst:321"/>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4492" version="1" class="vulnerability">
      <metadata>
        <title>Adobe Acrobat Reader libpng Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Acrobat Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed">
          <criterion comment="the software Adobe Acrobat Reader 6, major version 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:471"/>
          <criterion comment="the software Adobe Acrobat Reader 6, minor version less than 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:449" version="1" class="vulnerability">
      <metadata>
        <title>Bind OPT Resource Record DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1220" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1220"/>
        <description>BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via a request for a subdomain that does not exist, with an OPT resource record with a large UDP payload size.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 112970-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:447" version="1" class="vulnerability">
      <metadata>
        <title>Mutliple Buffer Management Errors in OpenSSH II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0693"/>
        <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2627"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:446" version="1" class="vulnerability">
      <metadata>
        <title>Memory Bugs in OpenSSH</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0682"/>
        <description>"Memory bugs" in OpenSSH 3.7.1 and earlier, with unknown impact, a different set of vulnerabilities than CVE-2003-0693 and CVE-2003-0695.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-11" negate="false" test_ref="oval:org.mitre.oval:tst:2627"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4458" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false" test_ref="oval:org.mitre.oval:tst:842"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:445" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSH Indirect User Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0190"/>
        <description>OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openssh-server version is less than 3.5p1-6.9" negate="false" test_ref="oval:org.mitre.oval:tst:2629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2628"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:444" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Temporary Internet Files folders Name Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1188"/>
        <description>Internet Explorer 5.01 through 6.0 allows remote attackers to identify the path to the Temporary Internet Files folder and obtain user information such as cookies via certain uses of the OBJECT tag, which are not subjected to the proper security checks, aka "Temporary Internet Files folders Name Reading."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4430" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos 5 KDC Buffer Underrun in Principle Name Handling</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0082"/>
        <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:26.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers SEAM</note>
      </notes>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
        <criteria operator="AND" comment="Patches 112536-04 and 110057-07 or later installed" negate="true">
          <criterion comment="Patch 112536-04 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:325"/>
          <criterion comment="Patch 110057-07 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:324"/>
        </criteria>
        <criterion comment="Patch 110060-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:323"/>
        <criterion comment="Patch 116462-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:322"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:443" version="1" class="vulnerability">
      <metadata>
        <title>mountd xlog Function Off-by-One Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>nfs-utils</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0252"/>
        <description>Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="nfs-utils version is less than 1.0.1-3.9" negate="false" test_ref="oval:org.mitre.oval:tst:2631"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.mountd listens on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2630"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:442" version="1" class="vulnerability">
      <metadata>
        <title>MYSQL Privilege Escalation Vulnerability via INFO OUTFILE Select</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>MySQL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0150"/>
        <description>MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SELECT * INFO OUTFILE" operator to overwrite a configuration file and cause mysql to run as root upon restart, as demonstrated by modifying my.cnf.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mysql-server version is less than 3.23.56-1.9" negate="false" test_ref="oval:org.mitre.oval:tst:2634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mysqld is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2633"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4416" version="1" class="vulnerability">
      <metadata>
        <title>Apache mod_digest Nonce Verification Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0987"/>
        <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:14:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:15:00.000-04:00" comment="Change apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:19:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:441" version="2">
      <metadata>
        <title>MHTML Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Outlook Express</product>
        </affected>
        <reference ref_id="CVE-2006-2766" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2766" source="CVE"/>
        <description>Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:26.625-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:40.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2900.2962" negate="false" test_ref="oval:org.mitre.oval:tst:55"/>
        </criteria>
        <criteria operator="AND">
          <criteria operator="OR">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
            <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          </criteria>
          <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2757" negate="false" test_ref="oval:org.mitre.oval:tst:11"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4403" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird XPInstall Security Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0762" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0762"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:440" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="the version of mscms.dll is less than 5.1.2600.1710" negate="false" test_ref="oval:org.mitre.oval:tst:2632"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:44" version="1" class="vulnerability">
      <metadata>
        <title>IIS Web Server Folder Traversal</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0884" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0884"/>
        <description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" negate="false" test_ref="oval:org.mitre.oval:tst:3023"/>
        <criterion comment="Patch Q269862 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3022"/>
        <criterion comment="Patch Q277873 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3021"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4397" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Object Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0550"/>
        <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
        <criteria operator="AND" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634">
          <criteria operator="OR" comment="Windows No Service Pack or Service Pack 1">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" negate="false" test_ref="oval:org.mitre.oval:tst:413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4392" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 NNTP Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0574"/>
        <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T08:47:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of nntpsvc.dll is less than 6.0.3790.206" negate="false" test_ref="oval:org.mitre.oval:tst:2759"/>
          <criterion comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" negate="true" test_ref="oval:org.mitre.oval:tst:326"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4384" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Message Queuing Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Message Queuing</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0059" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0059"/>
        <description>Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criterion comment="the version of mqrt.dll is less than 5.1.0.1044" negate="false" test_ref="oval:org.mitre.oval:tst:329"/>
          <criterion comment="the patch KB892944 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:328"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Message Queuing Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:327"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4383" version="1" class="vulnerability">
      <metadata>
        <title>lpq Buffer Overflow in bsd_queue()</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>lpstat</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0091" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0091"/>
        <description>Stack-based buffer overflow in the bsd_queue() function for lpq on Solaris 2.6 and 7 allows local users to gain root privilege.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:753"/>
        <criterion comment="Patch 107115-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:330"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:438" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.606-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.005 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3962"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4374" version="1" class="vulnerability">
      <metadata>
        <title>ToolTalk Buffer Overflow via TT_SESSION Envvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0693"/>
        <description>Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
        <criterion comment="Patch 107893-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:331"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4372" version="1" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (Terminal Server Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-24T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 4.0.1381.33618" negate="false" test_ref="oval:org.mitre.oval:tst:482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4368" version="1" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (32-bit XP, SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of lsasrv.dll is less than 5.1.2600.2525" negate="false" test_ref="oval:org.mitre.oval:tst:2623"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4363" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP3 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:436" version="1" class="vulnerability">
      <metadata>
        <title>MYSQLd Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>MySQL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0073"/>
        <description>Double-free vulnerability in mysqld for MySQL before 3.23.55 allows attackers with MySQL access to cause a denial of service (crash) via mysql_change_user.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mysql-server version is less than 3.23.56-1.9" negate="false" test_ref="oval:org.mitre.oval:tst:2634"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="mysqld is listening to the network" negate="false" test_ref="oval:org.mitre.oval:tst:2633"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:731" version="2">
      <metadata>
        <title>Microsoft IIS 5.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft IIS 5.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:36.527-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:48.090-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS Minor Version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:460" version="2">
      <metadata>
        <title>IIS 5.1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft IIS 5.1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:27.089-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.067-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS Minor Version equals 1" negate="false" test_ref="oval:org.mitre.oval:tst:1357"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:435" version="2">
      <metadata>
        <title>Internet Information Services using Malformed Active Server Pages Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>IIS</product>
        </affected>
        <reference ref_id="CVE-2006-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0026" source="CVE"/>
        <description>Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:26.215-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:40.456-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="IIS 5.0 is installed" definition_ref="oval:org.mitre.oval:def:731"/>
          <criterion comment="the version of asp.dll is less than 5.0.2195.7084" test_ref="oval:org.mitre.oval:tst:78"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <extend_definition comment="IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of asp.dll is less than 5.1.2600.1829" test_ref="oval:org.mitre.oval:tst:9"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of asp.dll is less than 5.1.2600.2889" test_ref="oval:org.mitre.oval:tst:157"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="IIS 5.1 is installed" definition_ref="oval:org.mitre.oval:def:460"/>
          <criterion comment="the version of asp.dll is less than 6.0.3790.2684" test_ref="oval:org.mitre.oval:tst:108"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="the version of asp.dll is less than 6.0.3790.520" test_ref="oval:org.mitre.oval:tst:144"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <extend_definition comment="IIS 6.0 is installed" definition_ref="oval:org.mitre.oval:def:227"/>
          <criterion comment="the version of asp.dll is less than 6.0.3790.2684" test_ref="oval:org.mitre.oval:tst:108"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4345" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Long Share Names Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0214"/>
        <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of shell32.dll is less than 5.0.3900.6970" negate="false" test_ref="oval:org.mitre.oval:tst:332"/>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:434" version="1" class="vulnerability">
      <metadata>
        <title>Mutt BO Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0140"/>
        <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="mutt version is less than 1.4.1-1" negate="false" test_ref="oval:org.mitre.oval:tst:2638"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/mutt is executable">
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2637"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2636"/>
            <criterion comment="/usr/bin/mutt is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2635"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:433" version="2">
      <metadata>
        <title>HTML Layout and Positioning Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3450" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3450" source="CVE"/>
        <description>Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using the document.getElementByID Javascript function to access crafted Cascading Style Sheet (CSS) elements, and possibly other unspecified vectors involving certain layout positioning combinations in an HTML file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:25.864-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:39.996-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4329" version="1" class="vulnerability">
      <metadata>
        <title>cachefsd DoS via Invalid RPC Request</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0085" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0085"/>
        <description>cachefsd in Solaris 2.6, 7, and 8 allows remote attackers to cause a denial of service (crash) via an invalid procedure call in an RPC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 108800-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3024"/>
          <criterion comment="Patch 110896-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2946"/>
          <criterion comment="Patch 114008-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3050"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4328" version="2" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Table Conversion Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:57.154-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 4.0.1381.7312" negate="false" test_ref="oval:org.mitre.oval:tst:441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4316" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 VDM Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0208"/>
        <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:08:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-13T01:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of vdmdbg.dll is less than 5.0.2195.6946" negate="false" test_ref="oval:org.mitre.oval:tst:333"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:431" version="2">
      <metadata>
        <title>Excel Malformed STYLE Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-3431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3431" source="CVE"/>
        <description>Buffer overflow in certain Asian language versions of Microsoft Excel might allow user-assisted attackers to execute arbitrary code via a crafted STYLE record in a spreadsheet that triggers the overflow when the user attempts to repair the document or selects the "Style" option, as demonstrated by nanika.xls.  NOTE: Microsoft has confirmed to CVE via e-mail that this is different than the other Excel vulnerabilities announced before 20060707, including CVE-2006-3059 and CVE-2006-3086.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:41.140-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:50.462-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:35"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6816.0" test_ref="oval:org.mitre.oval:tst:173"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8105.0" test_ref="oval:org.mitre.oval:tst:26"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:27"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4307" version="2" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (VS.NET 2002)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Studio .NET 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-30T11:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check KB830348.  Added check for VS.NET Gdiplus.dll in WinSxS.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 303 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:47.358-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Visual Studio .NET 2002 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:334"/>
        <criterion comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" negate="false" test_ref="oval:org.mitre.oval:tst:755"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:430" version="1" class="vulnerability">
      <metadata>
        <title>Multilingual File Viewer .lv File Sneak Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>lv</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0188"/>
        <description>lv reads a .lv file from the current working directory, which allows local users to execute arbitrary commands as other lv users by placing malicious .lv files into other directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="lv version is less than 4.49.4-9.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:2639"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:43" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 cachefsd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0084" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0084"/>
        <description>Buffer overflow in the fscache_setup function of cachefsd in Solaris 2.6, 7, and 8 allows local users to gain root privileges via a long mount argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Updated to add patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:25:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criterion comment="Patch 108800-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3024"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:429" version="2" class="vulnerability">
      <metadata>
        <title>MS Outlook (Word 2002) RTF/HTML Script Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1056"/>
        <description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-484 - Corrected registry key in path component">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:11:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:25.239-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of msohev.dll less than 10.0.2609.0" negate="false" test_ref="oval:org.mitre.oval:tst:2640"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4282" version="1" class="vulnerability">
      <metadata>
        <title>DHCP Server Logging Vulnerability (Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>DHCP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0899"/>
        <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-28T09:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" negate="false" test_ref="oval:org.mitre.oval:tst:335"/>
        <criterion comment="the patch KB885249 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:561"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:428" version="2">
      <metadata>
        <title>Server Service Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3942" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3942" source="CVE"/>
        <description>The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability.  NOTE: the name "Mailslot DOS" was derived from incomplete initial research; the vulnerability is not associated with a mailslot.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:40.466-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:49.665-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Srv.sys is less than 5.0.2195.7106" test_ref="oval:org.mitre.oval:tst:37"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Srv.sys is less than 5.1.2600.1885" test_ref="oval:org.mitre.oval:tst:39"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Srv.sys is less than 5.1.2600.2974" test_ref="oval:org.mitre.oval:tst:111"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.588" test_ref="oval:org.mitre.oval:tst:41"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Srv.sys is less than 5.2.3790.2783" test_ref="oval:org.mitre.oval:tst:40"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4276" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (64-Bit) DUNZIP Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Compressed Folders</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0575"/>
        <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-05T12:00:00.000-04:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" negate="false" test_ref="oval:org.mitre.oval:tst:336"/>
          <criterion comment="the patch q873376 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1236"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Compressed Folders with zipfldr.dll are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1235"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:427" version="2">
      <metadata>
        <title>Microsoft Publisher 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Publisher 2000 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.243-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.950-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Publisher 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:22"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4264" version="2" class="vulnerability">
      <metadata>
        <title>ISA Server Reverse DNS Lookup Results Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>ISA Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0892" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0892"/>
        <description>Microsoft Proxy Server 2.0 and Microsoft ISA Server 2000 (which is included in Small Business Server 2000 and Small Business Server 2003 Premium Edition) allows remote attackers to spoof trusted Internet content on a specially crafted webpage via spoofed reverse DNS lookup results.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-24T12:00:00.000-04:00" comment="modified var 208 to correctly point at the ISA Server directory">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-24T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:25.022-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msphlpr.dll is less than 3.0.1200.408" negate="false" test_ref="oval:org.mitre.oval:tst:338"/>
        <criterion comment="ISA Server 2000 SP2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2611"/>
        <criterion comment="the patch KB888258 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:337"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4254" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Cluster</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0543" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0543"/>
        <description>Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:10:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113505-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:511"/>
          <criterion comment="Patch 113508-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:510"/>
          <criterion comment="Patch 115054-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:509"/>
          <criterion comment="Patch 115055-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:508"/>
          <criterion comment="SunCluster Component SUNWscvw installed" negate="false" test_ref="oval:org.mitre.oval:tst:507"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running with SunPlex Manager config" negate="false" test_ref="oval:org.mitre.oval:tst:506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4244" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2003 (32-Bit) Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criterion comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" negate="false" test_ref="oval:org.mitre.oval:tst:339"/>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:424" version="1" class="vulnerability">
      <metadata>
        <title>Windows Telnet Server Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Telnet protocol</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0020"/>
        <description>Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-20T12:00:00.000-04:00" comment="Changed patch registry key value to IsInstalled">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-11T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of tlntsvr.exe is less than 5.0.33668.1" negate="false" test_ref="oval:org.mitre.oval:tst:2644"/>
          <criterion comment="Patch Q307298 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2643"/>
          <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the telnet service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2642"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4234" version="2" class="vulnerability">
      <metadata>
        <title>Word 2003 Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:24.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of winword.exe is less than 11.0.6502.0" negate="false" test_ref="oval:org.mitre.oval:tst:713"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:423" version="1" class="vulnerability">
      <metadata>
        <title>LPRng Symbolic Link Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>LPRng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0136" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0136"/>
        <description>psbanner in the LPRng package allows local users to overwrite arbitrary files via a symbolic link attack on the /tmp/before file.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="lprng version is less than 3.8.19-3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2647"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="psbanner is world-executable" negate="false" test_ref="oval:org.mitre.oval:tst:2646"/>
          <criterion comment="lpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2645"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4224" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (32-bit) RPCSS DCOM Buffer Overflow (Blaster)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.109" negate="false" test_ref="oval:org.mitre.oval:tst:556"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4216" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (IE6)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T09:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check q833989, added check for vgx.dll.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of vgx.dll is less than 6.0.2800.1411" negate="false" test_ref="oval:org.mitre.oval:tst:341"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:421" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:47.099-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.727-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.23 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3193"/>
        <criterion comment="Patch PHNE_33412 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:4132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:420" version="3" class="vulnerability">
      <metadata>
        <title>Word 2003 (wordview) Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:24.499-04:00">ACCEPTED</status_change>
            <modified date="2006-10-12T16:02:00.000-04:00" comment="Fixed filename typo in obj:1517 (referenced by tst:2648): ordview.exe to wordview.exe.">
              <contributor organization="Assuria Ltd.">Chris Wood</contributor>
            </modified>
            <status_change date="2006-10-12T16:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:39.458-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of wordview.exe is less than 11.0.6506.0" negate="false" test_ref="oval:org.mitre.oval:tst:2648"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:42" version="2" class="vulnerability">
      <metadata>
        <title>Solaris 7 RPC xdr_array Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libnsl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0391" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0391"/>
        <description>Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:24.285-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criteria operator="OR" comment="rpc.cmsd or dmispd exist">
            <criterion comment="File rpc.cmsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3140"/>
            <criterion comment="File dmispd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3139"/>
          </criteria>
          <criteria operator="AND" comment="Patches 106942-22 and 108451-06" negate="true">
            <criterion comment="Patch 106942-22 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3026"/>
            <criterion comment="Patch 108541-06 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:3025"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="rpc.cmsd enabled OR dmispd running">
            <criteria operator="AND" comment="rpc.cmsd enabled">
              <criterion comment="" negate="false" test_ref="oval:org.mitre.oval:tst:3136"/>
              <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
              <criteria operator="OR" comment="File rpc.cmsd executable">
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3134"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3133"/>
                <criterion comment="File rpc.cmsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3132"/>
              </criteria>
            </criteria>
            <criterion comment="dmispd running" negate="false" test_ref="oval:org.mitre.oval:tst:3131"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4190" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in DNS Resolver Library</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0651" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0651"/>
        <description>Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 106938-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:345"/>
          <criterion comment="Patch 109326-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:344"/>
          <criterion comment="Patch 112970-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:343"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/nsswitch.conf configured to resolve hosts through DNS" negate="false" test_ref="oval:org.mitre.oval:tst:342"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:417" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 InstallVersion.compareTo() DoS and Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2265"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4169" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP, IE v6.0 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:416" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4152" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:412" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.966-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4114" version="1" class="vulnerability">
      <metadata>
        <title>Apache Error Log Escape Sequence Injection Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020"/>
        <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:14:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:14:00.000-04:00" comment="Change apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:18:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:411" version="1" class="vulnerability">
      <metadata>
        <title>KDE Konqueror Userid/Password Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Konqueror</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0459" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0459"/>
        <description>KDE Konqueror for KDE 3.1.2 and earlier does not remove authentication credentials from URLs of the "user:password@host" form in the HTTP-Referer header, which could allow remote web sites to steal the credentials for pages that link to the sites.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdelibs version is less than 3.1-12" negate="false" test_ref="oval:org.mitre.oval:tst:2656"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/konqueror is executable">
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2655"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2654"/>
            <criterion comment="/usr/bin/konqueror is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2653"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:410" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.831-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3519"/>
        <criterion comment="Patch PHNE_34077 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:41" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 RWall Daemon Syslog Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>rpc.rwalld</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0573"/>
        <description>Format string vulnerability in RPC wall daemon (rpc.rwalld) for Solaris 2.5.1 through 8 allows remote attackers to execute arbitrary code via format strings in a message that is not properly provided to the syslog function when the wall command cannot be executed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.rwalld exists" negate="false" test_ref="oval:org.mitre.oval:tst:3032"/>
          <criterion comment="Patch 112899-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3031"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.rwalld" negate="false" test_ref="oval:org.mitre.oval:tst:3030"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.rwalld executable">
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3029"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3028"/>
            <criterion comment="File rpc.rwalld executable" negate="false" test_ref="oval:org.mitre.oval:tst:3027"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4098" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vulnerabilities in lpstat and libprint</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>lpstat, libprint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0999" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0999"/>
        <description>Unknown multiple vulnerabilities in (1) lpstat and (2) the libprint library in Solaris 2.6 through 9 may allow attackers to execute arbitrary code or read or write arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Solaris Printing Services installed (any SUNWpcr/SUNWpcu/SUNWpsr/SUNWpsu)">
          <criterion comment="Solaris Print - Client - Root (SUNWpcr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:352"/>
          <criterion comment="Solaris Print - Client - Usr (SUNWpcu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:351"/>
          <criterion comment="Solaris Print - LP Server - Root (SUNWpsr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:350"/>
          <criterion comment="Solaris Print - LP Server - Usr (SUNWpsu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:349"/>
        </criteria>
        <criterion comment="Patch 107115-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:348"/>
        <criterion comment="Patch 109320-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:347"/>
        <criterion comment="Patch 113329-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:346"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:409" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4085" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP2 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-159 - unchecked value">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false" test_ref="oval:org.mitre.oval:tst:2402"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:408" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Cross Domain Verification via Cached Methods Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1254"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4076" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed: Duplicate of OVAL1655</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-35 - wrt-35 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the patch kb885836 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1104"/>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of mswrd632.wpc is less than 2004.10.25.0" negate="false" test_ref="oval:org.mitre.oval:tst:1103"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Word for Windows 6.0 Converter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2421"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:407" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (32-bit Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Microsoft Windows Server 2003 32-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.280" negate="false" test_ref="oval:org.mitre.oval:tst:2658"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2657"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:406" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Winsock Proxy Service Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>ISA Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0110" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0110"/>
        <description>The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed packet to UDP port 1745.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="ISA Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2935"/>
          <criterion comment="the version of w3proxy.exe is less than 3.0.1200.257" negate="false" test_ref="oval:org.mitre.oval:tst:2662"/>
          <criterion comment="the version of wpsrv.exe is less than 3.0.1200.257" negate="false" test_ref="oval:org.mitre.oval:tst:2661"/>
          <criterion comment="Patch isahf257 installed" negate="true" test_ref="oval:org.mitre.oval:tst:2660"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Microsoft Firewall Service Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2659"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:405" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.701-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:54.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4047" version="2" class="vulnerability">
      <metadata>
        <title>Shell Redirect Symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <product>Bourne Shell (sh)</product>
          <product>Bourne Again Shell (bash)</product>
          <product>TENEX C Shell (tcsh)</product>
          <product>C Shell (csh)</product>
          <product>Korn Shell (ksh)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1134"/>
        <description>Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing &lt;&lt;redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-13T03:18:00.000-04:00" comment="Added Sun Solaris 8 to list of platforms in Affected metadata.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-27T12:29:23.796-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 installed">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        </criteria>
        <criteria operator="AND" comment="Patches 108574-03, 108162-04, and 108416-02 or later installed" negate="true">
          <criterion comment="Patch 108574-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:358"/>
          <criterion comment="Patch 108162-04 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:357"/>
          <criterion comment="Patch 108416-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:356"/>
        </criteria>
        <criteria operator="AND" comment="Patches 110943-01, 110898-02, and 109324-03 or later installed" negate="true">
          <criterion comment="Patch 110943-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:355"/>
          <criterion comment="Patch 110898-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:354"/>
          <criterion comment="Patch 109324-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:353"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4043" version="1" class="vulnerability">
      <metadata>
        <title>SMB Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0045"/>
        <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.0.2195.7023" negate="false" test_ref="oval:org.mitre.oval:tst:359"/>
        <criterion comment="the patch KB885250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4032" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server SMTP Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0560"/>
        <description>Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:362"/>
        <criterion comment="the version of xlsasink.dll is less than 6.5.6981.3" negate="false" test_ref="oval:org.mitre.oval:tst:361"/>
        <criterion comment="the patch KB894549 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:360"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4030" version="1" class="vulnerability">
      <metadata>
        <title>DtMail Local Command Line Format String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>DtMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0800" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0800"/>
        <description>Format string vulnerability in CDE Mailer (dtmail) on Solaris 8 and 9 allows local users to gain privileges via format strings in the argv[0] value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 109613-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:365"/>
        <criterion comment="Patch 112810-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:364"/>
        <criterion comment="CDE Desktop Applications (SUNWdtdst) installed" negate="false" test_ref="oval:org.mitre.oval:tst:363"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:403" version="1" class="vulnerability">
      <metadata>
        <title>Code Execution via Compiled HTML Help File</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0694"/>
        <description>The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of hhsetup.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2675"/>
        <criterion comment="the version of itircl.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2674"/>
        <criterion comment="the version of itss.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2673"/>
        <criterion comment="the patch q323255 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2672"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4022" version="2" class="vulnerability">
      <metadata>
        <title>Office XP URL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office XP SP3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0848"/>
        <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenamesor (2) "%0a" (carriage return) in .rtf filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2005-02-11T12:00:00.000-04:00" comment="Added patch check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-03-29T12:00:00.000-04:00" comment="corrected patch negation">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2006-09-21T12:00:00.000-04:00" comment="removed tst:366 since it doesn't detect KB873352 correctly">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2006-09-21T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:46.501-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1592"/>
        <criterion comment="the version of mso.dll is less than 10.0.6735.0" negate="false" test_ref="oval:org.mitre.oval:tst:554"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4021" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (NT Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" negate="false" test_ref="oval:org.mitre.oval:tst:367"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:402" version="1" class="vulnerability">
      <metadata>
        <title>SNMP Request Handling Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0053"/>
        <description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-15T12:43:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-09-15T03:43:00.000-04:00" comment="Filled out initial submission.  Now a complete definition.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-09-22T02:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:401" version="1" class="vulnerability">
      <metadata>
        <title>C-Media Sound Driver Userspace Access Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0700" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0700"/>
        <description>The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4005" version="1" class="vulnerability">
      <metadata>
        <title>Office XP, SP2 WordPerfect Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XP SP2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0573"/>
        <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-489 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:375"/>
        <criterion comment="the version of msconv97.dll is less than 2003.1100.6252.0" negate="false" test_ref="oval:org.mitre.oval:tst:492"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4003" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Windows XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>GDI+</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-20T03:32:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-22T02:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check KB833987.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the version of sxs.dll is less than 5.1.2600.1363" negate="false" test_ref="oval:org.mitre.oval:tst:368"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:40" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 GetObject File Retrieval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3122"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:973" version="2">
      <metadata>
        <title>Microsoft Word 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Word 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:52.155-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:03.268-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:737" version="2">
      <metadata>
        <title>Microsoft Word Viewer is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Word Viewer is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:50.456-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:28:01.162-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Word Viewer is installed" negate="false" test_ref="oval:org.mitre.oval:tst:38"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:455" version="2">
      <metadata>
        <title>Microsoft Word 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Word 2000 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:42.657-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:52.358-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:4" version="2">
      <metadata>
        <title>Microsoft Word Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference ref_id="CVE-2006-3647" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3647" source="CVE"/>
        <description>Integer overflow in Microsoft Word 2000, 2002, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string in a Word document, which overflows a 16-bit integer length value, aka "Memmove Code Execution," a different vulnerability than CVE-2006-3651 and CVE-2006-4693.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:38.550-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:48.208-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8951" test_ref="oval:org.mitre.oval:tst:57"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6818.0" test_ref="oval:org.mitre.oval:tst:107"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8106.0" test_ref="oval:org.mitre.oval:tst:151"/>
        </criteria>
        <criteria comment="Word Viewer" operator="AND">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of wordview.exe is less than 11.0.8104.0" test_ref="oval:org.mitre.oval:tst:28"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3994" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Access Requests Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0061"/>
        <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
        <criteria operator="AND" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634">
          <criteria operator="OR" comment="Windows No Service Pack or Service Pack 1">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" negate="false" test_ref="oval:org.mitre.oval:tst:413"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:399" version="2">
      <metadata>
        <title>Microsoft PowerPoint Mso.dll Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3590" source="CVE"/>
        <description>mso.dll, as used by Microsoft PowerPoint 2000 through 2003, allows user-assisted attackers to execute arbitrary commands via a malformed shape container in a PPT file that leads to memory corruption, as exploited by Trojan.PPDropper.B, a different issue than CVE-2006-1540 and CVE-2006-3493.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:23.583-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:39.372-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="PowerPoint 2000" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8948" test_ref="oval:org.mitre.oval:tst:16"/>
        </criteria>
        <criteria comment="PowerPoint 2002" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6811.0" test_ref="oval:org.mitre.oval:tst:17"/>
        </criteria>
        <criteria comment="PowerPoint 2003" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8036.0" test_ref="oval:org.mitre.oval:tst:110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3989" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox Certificate Spoofing Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0763" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0763"/>
        <description>Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3973" version="2" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-226 - access DLL via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:56.114-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of hypertrm.dll is less than 4.0.1381.7323" negate="false" test_ref="oval:org.mitre.oval:tst:370"/>
          <criterion comment="the patch NT Server kb873339 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:369"/>
          <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:397" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Kerberos</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1174"/>
        <description>MIT Kerberos 5 (krb5) 1.3 through 1.4.1 Key Distribution Center (KDC) allows remote attackers to cause a denial of service (application crash) via a certain valid TCP connection that causes a free of unallocated memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.201-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112536-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3576"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112537-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3424"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112237-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3567"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 112238-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3898"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112390-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3640"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) with Supplmental Encryption Packages meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criteria operator="OR" comment="Solaris Supplemental Encryption Packages are installed" negate="false">
            <criterion comment="Pkg SUNWcry (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3198"/>
            <criterion comment="Pkg SUNWcryr (Supplemental Encryption) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3694"/>
          </criteria>
          <criterion comment="Patch 112240-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3497"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112908-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3389"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 115168-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3624"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120469-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3561"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101809 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
          <criterion comment="Patch 120470-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3418"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3966" version="1" class="vulnerability">
      <metadata>
        <title>RPCSS DCOM Buffer Overflow (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0528"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.76" negate="false" test_ref="oval:org.mitre.oval:tst:1080"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3960" version="1" class="vulnerability">
      <metadata>
        <title>in.named Process Crash Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1348" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1348"/>
        <description>Unknown vulnerability in in.named on Solaris 8 allows remote attackers to cause a denial of service (process crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 109326-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:372"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="File /etc/named.conf exists" negate="false" test_ref="oval:org.mitre.oval:tst:371"/>
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3957" version="1" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (NT 4.0 Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="the version of user32.dll is less than 4.0.1381.33630" negate="false" test_ref="oval:org.mitre.oval:tst:454"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3953" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT VDM Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0208"/>
        <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T12:05:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:55.926-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="the version of gdi32.dll is less than 4.0.1381.7270" negate="false" test_ref="oval:org.mitre.oval:tst:373"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3949" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01, SP3 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3941" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Font Buffer Overflow (SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0060"/>
        <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false" test_ref="oval:org.mitre.oval:tst:2738"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:393" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Malformed PNG Image File Failure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1185"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly check certain parameters of a PNG file when opening it, which allows remote attackers to cause a denial of service (crash) by triggering a heap-based buffer overflow using invalid length codes during decompression, aka "Malformed PNG Image File Failure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3926" version="2" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:23.314-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:392" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 (XP) ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-21T05:00:00.000-04:00" comment="Removed the test for Windows XP.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Removed the IE 6 SP 1 part of this definition as the SP 1 part is defined in a different OVAL.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2734.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2663"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3913" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (32-Bit) DUNZIP Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Compressed Folders</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0575"/>
        <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-05T12:00:00.000-04:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" negate="false" test_ref="oval:org.mitre.oval:tst:374"/>
          <criterion comment="the patch q873376 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1236"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Compressed Folders with zipfldr.dll are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1235"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3910" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:390" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 JPEG Image Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1988"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:39" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS HTTP Header Field Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0150"/>
        <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:389" version="2">
      <metadata>
        <title>Office Improper Memory Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-3434" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3434" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac allows remote user-assisted attackers to execute arbitrary code via a crafted string that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:37.963-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:47.378-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:33"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6817.0" test_ref="oval:org.mitre.oval:tst:158"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8107.0" test_ref="oval:org.mitre.oval:tst:98"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3889" version="1" class="vulnerability">
      <metadata>
        <title>Help and Support Center PCHealth System Buffer Overflow (32-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Help and Support Center</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0711"/>
        <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
          <criterion comment="the version of itircl.dll is less than 5.2.3790.80" negate="false" test_ref="oval:org.mitre.oval:tst:2792"/>
          <criterion comment="Patch KB825119 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2791"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HCP Protocol" negate="false" test_ref="oval:org.mitre.oval:tst:2789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3882" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Font Conversion Vulnerability (32-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) dropped version checks on mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 5.1.2600.1606" negate="false" test_ref="oval:org.mitre.oval:tst:666"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3881" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Office XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XP SP2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-06T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-496 - corrected registry path check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB832332.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:375"/>
        <criterion comment="the version of mso.dll is less than 10.0.6714.0" negate="false" test_ref="oval:org.mitre.oval:tst:463"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:388" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Cross Domain Verification via Cached Methods Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1254"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached Methods."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3872" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:23.055-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:387" version="1" class="vulnerability">
      <metadata>
        <title>C-Media Sound Driver Userspace Access Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0699"/>
        <description>The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:386" version="1" class="vulnerability">
      <metadata>
        <title>Lunix Kernel NFSv3 Procedure Kernel Panic Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0619" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0619"/>
        <description>Integer signedness error in the decode_fh function of nfs3xdr.c in Linux kernel before 2.4.21 allows remote attackers to cause a denial of service (kernel panic) via a negative size value within XDR data of an NFSv3 procedure call.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3851" version="1" class="vulnerability">
      <metadata>
        <title>IE AbusiveParent Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
        <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of dhtmled.ocx is less than 6.1.0.9232" negate="false" test_ref="oval:org.mitre.oval:tst:427"/>
        <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:385" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel Bridge Forwarding Table Spoof Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0552" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0552"/>
        <description>Linux 2.4.x allows remote attackers to spoof the bridge Forwarding table via forged packets whose source addresses are the same as the target.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:384" version="1" class="vulnerability">
      <metadata>
        <title>STP Protocol Length Verification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0551"/>
        <description>The STP protocol implementation in Linux 2.4.x does not properly verify certain lengths, which could allow attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3831" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in ntp Daemon via readvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <product>sendfilev()</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0414" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0414"/>
        <description>Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long readvar argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criterion comment="NTP daemon - Usr (SUNWntpu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:379"/>
          <criterion comment="Patch 109409-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:378"/>
          <criterion comment="Patch 109667-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:377"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="xntpd running" negate="false" test_ref="oval:org.mitre.oval:tst:376"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3826" version="2" class="vulnerability">
      <metadata>
        <title>WinXP Path MTU Discovery Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-22T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:55.555-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
          <criteria operator="OR" comment="A vulnerable version of tcpip.sys is installed.">
            <criteria operator="AND" comment="Service Pack 1 is installed and tcpip.sys is less than 5.1.2600.1693">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1693" negate="false" test_ref="oval:org.mitre.oval:tst:776"/>
            </criteria>
            <criteria operator="AND" comment="Service Pack 2 is installed and tcpip.sys is less than 5.1.2600.2685">
              <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
              <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2685" negate="false" test_ref="oval:org.mitre.oval:tst:775"/>
            </criteria>
          </criteria>
          <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Enable Path MTU Discovery is Disabled" negate="true" test_ref="oval:org.mitre.oval:tst:2352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3824" version="2" class="vulnerability">
      <metadata>
        <title>Win2k IP Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0048"/>
        <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:55.361-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3822" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) Program Group Converter Buffer Overflow in shell32.dll</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:39:00.000-04:00" comment="modified wft-509 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criteria operator="OR" comment="a vulnerable version of shell32.dll exists">
          <criterion comment="the version of shell32.dll is less than 6.0.2800.1580" negate="false" test_ref="oval:org.mitre.oval:tst:381"/>
          <criterion comment="the version of shell32.dll (WOW64) is less than 6.0.2800.1580" negate="false" test_ref="oval:org.mitre.oval:tst:380"/>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:382" version="1" class="vulnerability">
      <metadata>
        <title>gzip Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1228"/>
        <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false" test_ref="oval:org.mitre.oval:tst:2667"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="/usr/bin/gzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2666"/>
          <criterion comment="/usr/bin/gunzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2665"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3817" version="1" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE6 for XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2627" negate="false" test_ref="oval:org.mitre.oval:tst:768"/>
          <criterion comment="the patch kb890923  is installed (XP SP2 Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:767"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3810" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Project 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Project Professional 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-495 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB838344.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Project Professional 2003 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:382"/>
        <criterion comment="the version of gdiplus.dll is less than 6.0.3264.0" negate="false" test_ref="oval:org.mitre.oval:tst:438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:381" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 HTML Help Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1208"/>
        <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of hh.exe exists">
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of hh.exe exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of hh.exe is less than 5.2.3790.315" negate="false" test_ref="oval:org.mitre.oval:tst:2671"/>
          </criteria>
          <criteria operator="AND" comment="   for specific Windows configurations a vulnerable version of hh.exe exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of hh.exe is less than 5.2.3790.2427" negate="false" test_ref="oval:org.mitre.oval:tst:2670"/>
          </criteria>
          <criteria operator="AND" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of hh.exe exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of hh.exe is less than 5.2.3790.2435" negate="false" test_ref="oval:org.mitre.oval:tst:2669"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb896358 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2668"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:380" version="1" class="vulnerability">
      <metadata>
        <title>Insecure Design of the STP Protocol</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0550"/>
        <description>The STP protocol, as enabled in Linux 2.4.x, does not provide sufficient security by design, which allows attackers to modify the bridge topology.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:38" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Group Policy Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0051"/>
        <description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-09-26T10:55:00.000-04:00" comment="modified wft-212 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:55.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (domain controller) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
        </criteria>
        <criterion comment="the version of srvsvc.dll is less than 5.0.2195.4980" negate="false" test_ref="oval:org.mitre.oval:tst:3034"/>
        <criterion comment="Patch Q318593 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3033"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3799" version="1" class="vulnerability">
      <metadata>
        <title>Apache Web Server Multiple Module Local Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0542" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0542"/>
        <description>Multiple stack-based buffer overflows in (1) mod_alias and (2) mod_rewrite for Apache before 1.3.29 allow attackers to create configuration files to cause a denial of service (crash) or execute arbitrary code via a regular expression with more than 9 captures.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:08:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113146-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:383"/>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:379" version="2">
      <metadata>
        <title>Microsoft Excel Malformed SELECTION record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1302" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1302" source="CVE"/>
        <description>Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:22.815-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:39.105-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3773" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:42:00.000-04:00" comment="modified wft-562 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4945.2800" negate="false" test_ref="oval:org.mitre.oval:tst:384"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:377" version="2">
      <metadata>
        <title>.NET Framework 2.0 Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>.NET Framework</product>
        </affected>
        <reference ref_id="CVE-2006-3436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3436" source="CVE"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft .NET Framework 2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "ASP.NET controls that set the AutoPostBack property to true".</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:37.503-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:46.838-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="The .NET Framework v2.0 is installed" definition_ref="oval:org.mitre.oval:def:310"/>
        <criterion comment="the version of Aspnet_filter.dll is less than 2.0.50727.101" test_ref="oval:org.mitre.oval:tst:42"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3768" version="1" class="vulnerability">
      <metadata>
        <title>Windows ME Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows ME Installed" negate="false" test_ref="oval:org.mitre.oval:tst:831"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:376" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:46.068-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3750"/>
        <criterion comment="SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3341"/>
        <criterion comment="rdpwd.sys is less than 5.1.2600.2695" negate="false" test_ref="oval:org.mitre.oval:tst:3639"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3752" version="2" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE6,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:1340 - Set xsi:nil to true on the name entity as we are only concerned with the existance of the key itself.">
              <contributor organization="Centennial Software">Jason Spashett</contributor>
            </modified>
            <status_change date="2006-06-23T12:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:22.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" negate="false" test_ref="oval:org.mitre.oval:tst:2338"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" negate="false" test_ref="oval:org.mitre.oval:tst:2337"/>
          </criteria>
          <criterion comment="the patch kb890923 is installed (XP Win2K Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2336"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3743" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Table Conversion Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Replaced all criteria. 1) Included all S03 versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false" test_ref="oval:org.mitre.oval:tst:2570"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:374" version="2" class="vulnerability">
      <metadata>
        <title>HTML Help ActiveX Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help ActiveX Control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0693"/>
        <description>Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:22.284-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of hhctrl.ocx is less than 5.2.3669.0" negate="false" test_ref="oval:org.mitre.oval:tst:2676"/>
          <criterion comment="the version of hhsetup.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2675"/>
          <criterion comment="the version of itircl.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2674"/>
          <criterion comment="the version of itss.dll is less than 5.2.3644.0" negate="false" test_ref="oval:org.mitre.oval:tst:2673"/>
          <criterion comment="the patch q323255 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2672"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:373" version="1" class="vulnerability">
      <metadata>
        <title>IIS AddHeader Large Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0225" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0225"/>
        <description>The ASP function Response.AddHeader in Microsoft Internet Information Server (IIS) 4.0 and 5.0 does not limit memory requests when constructing headers, which allow remote attackers to generate a large header to cause a denial of service (memory consumption) with an ASP page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" negate="false" test_ref="oval:org.mitre.oval:tst:2988"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:372" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:371" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:370" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:37" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Directory Traversal Command Execution (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" negate="false" test_ref="oval:org.mitre.oval:tst:3039"/>
        <criterion comment="Patch Q295534 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3038"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Windows NT 4.0 Security Roll-up Package" negate="true" test_ref="oval:org.mitre.oval:tst:3036"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:369" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3685" version="2" class="vulnerability">
      <metadata>
        <title>Help and Support Center PCHealth System Buffer Overflow (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0711"/>
        <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:22.075-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="Patch KB825119 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2791"/>
          <criterion comment="the version of itircl.dll is less than 5.2.3790.80" negate="false" test_ref="oval:org.mitre.oval:tst:2792"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HCP Protocol" negate="true" test_ref="oval:org.mitre.oval:tst:2789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:368" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 HijackClick Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0823" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0823"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to direct drag and drop behaviors and other mouse click actions to other windows by calling the window.moveBy method, aka HijackClick, a different vulnerability than CVE-2003-1027.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3677" version="1" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (64-bit Server 2003, Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="this is an NT Workstation" negate="true" test_ref="oval:org.mitre.oval:tst:2703"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.2.3790.239" negate="false" test_ref="oval:org.mitre.oval:tst:866"/>
          <criterion comment="the patch KB870763 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:865"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:367" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft SharePoint Team Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:52:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists">
            <criterion comment="the version of fp5areg.dll is less than 10.00.4205.0000" negate="false" test_ref="oval:org.mitre.oval:tst:2679"/>
            <criterion comment="the version of fp30reg.dll is less than 10.00.4205.0000" negate="false" test_ref="oval:org.mitre.oval:tst:2678"/>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:366" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp5areg.dll instead of fp5awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:51:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows NT, 2000, or XP is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp5areg.dll exists">
            <criterion comment="the version of fp5areg.dll is less than 10.00.4205.0000" negate="false" test_ref="oval:org.mitre.oval:tst:2679"/>
            <criterion comment="the version of fp30reg.dll is less than 10.00.4205.0000" negate="false" test_ref="oval:org.mitre.oval:tst:2678"/>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2677"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3657" version="1" class="vulnerability">
      <metadata>
        <title>Portable Network Graphics Library Offset Calculation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1363" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1363"/>
        <description>Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-03T04:26:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-09-08T10:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="libpng or libpng-devel rpm older than 1.2.2-24, Epoch 2 OR libpng10or libpng10-devel rpm older than 1.0.13-14, Epoch 0">
          <criterion comment="libpng rpm older than 1.2.2-24, Epoch 2" negate="false" test_ref="oval:org.mitre.oval:tst:388"/>
          <criterion comment="libpng-devel rpm older than 1.2.2-24, Epoch 2" negate="false" test_ref="oval:org.mitre.oval:tst:387"/>
          <criterion comment="libpng10-devel rpm older than 1.0.13-14, Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:386"/>
          <criterion comment="libpng10 rpm older than 1.0.13-14, Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:364" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions Chunked Encoded Request Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0822" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0822"/>
        <description>Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackers to execute arbitrary code via a crafted chunked encoded request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Changed the definition to test for fp30reg.dll and fp4areg.dll instead of fp4awel.dll.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:50:00.000-04:00" comment="modified wft-114 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-31 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of fp30reg.dll or fp4areg.dll exists">
            <criterion comment="the version of fp4areg.dll is less than 4.0.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2681"/>
            <criterion comment="the version of fp30reg.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2680"/>
          </criteria>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3637" version="1" class="vulnerability">
      <metadata>
        <title>priocntl Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>priocntl()</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1296"/>
        <description>Directory traversal vulnerability in priocntl system call in Solaris does allows local users to execute arbitrary code via ".." sequences in the pc_clname field of a pcinfo_t structure, which cause priocntl to load a malicious kernel module.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 106541-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:546"/>
        <criterion comment="Patch 108528-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:390"/>
        <criterion comment="Patch 112233-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:389"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:363" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:362" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:361" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Script URLs Cross Domain Zone Restrictions Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0816" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0816"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions by (1) using the NavigateAndFind method to load a file: URL containing Javascript, as demonstrated by NAFfileJPU, (2) using the window.open method to load a file: URL containing Javascript, as demonstrated using WsOpenFileJPU, (3) setting the href property in the base tag for the _search window, as demonstrated using WsBASEjpu, (4) loading the search window into an Iframe, as demonstrated using WsFakeSrc, (5) caching a javascript: URL in the browser history, then accessing that URL in the same frame as the target domain, as demonstrated using WsOpenJpuInHistory, NAFjpuInHistory, BackMyParent, BackMyParent2, and RefBack, aka the "Script URLs Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3604" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T01:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT 4.0 with Active Desktop Installed">
          <criterion comment="Active Desktop  is installed" negate="false" test_ref="oval:org.mitre.oval:tst:743"/>
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        </criteria>
        <criterion comment="the version of shell32.dll is less than 4.72.3841.1100" negate="false" test_ref="oval:org.mitre.oval:tst:394"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3603" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird Security Lock Icon Spoof Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0761" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0761"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lock icon that makes a web page appear to be encrypted.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3601" version="1" class="vulnerability">
      <metadata>
        <title>Runtime linker, ld.so.1 LD_PRELOAD Envvar Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Solaris Runtime Linker</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0609" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0609"/>
        <description>Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root privileges via a long LD_PRELOAD environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Solaris 9 OR Patch 106950-14+ OR Patch 109147-07+ installed">
          <criterion comment="Patch 106950-14 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:397"/>
          <criterion comment="Patch 109147-07 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:396"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 106950-14 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:397"/>
        <criterion comment="Patch 109147-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:396"/>
        <criterion comment="Patch 112963-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:360" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 8</platform>
          <product>Access Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0531"/>
        <description>Unspecified vulnerability in Sun Java System Access Manager 7.0 allows local users logged in as "root" to bypass authentication and gain top-level administrator privileges via the amadmin CLI tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.919-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SPARC" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
        <criterion comment="Sun Java System Access Manager 7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3551"/>
        <criterion comment="Patch 120954-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:36" version="1" class="inventory">
      <metadata>
        <title>Microsoft Windows NT is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows NT.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="the installed operating system is part of the Microsoft Windows family"/>
        <criterion test_ref="oval:org.mitre.oval:tst:1" comment="Windows NT is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:359" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003)  Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false" test_ref="oval:org.mitre.oval:tst:2686"/>
          <criterion comment="the patch q824145 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2685"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3586" version="1" class="vulnerability">
      <metadata>
        <title>IE6.0,SP1 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" negate="false" test_ref="oval:org.mitre.oval:tst:1329"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" negate="false" test_ref="oval:org.mitre.oval:tst:1328"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3585" version="1" class="vulnerability">
      <metadata>
        <title>Web View Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1191"/>
        <description>The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a mailto: link for the preview pane when the user selects the file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-06-01T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of webvw.dll is less than 5.0.3900.7036" negate="false" test_ref="oval:org.mitre.oval:tst:400"/>
          <criterion comment="the patch KB894320 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:399"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Webview is  Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3582" version="1" class="vulnerability">
      <metadata>
        <title>License Logging Service Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>MDAC 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0050"/>
        <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T11:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Corrected Windows Server 2003 test logic">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the patch kb885834 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2477"/>
          <criterion comment="the version of Llssrv.exe is less than 5.2.3790.242" negate="false" test_ref="oval:org.mitre.oval:tst:401"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="license logging service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:358" version="1" class="vulnerability">
      <metadata>
        <title>cpio Race Condition</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>cpio</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1111"/>
        <description>Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-08T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-09T07:56:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-24T09:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cpio rpm is older than 0:2.5-4.RHEL3" negate="false" test_ref="oval:org.mitre.oval:tst:2683"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/bin/cpio is executable by all" negate="false" test_ref="oval:org.mitre.oval:tst:2682"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3577" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT DHCP Request Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>DHCP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0900" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0900"/>
        <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition does not properly validate the length of certain messages, which allows remote attackers to execute arbitrary code via a malformed DHCP message, aka the"DHCP Request Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-28T09:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:54.845-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" negate="false" test_ref="oval:org.mitre.oval:tst:562"/>
        <criterion comment="the patch KB885249 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:561"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3573" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed OVAL3573</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <product>MDAC 2.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for MDAC 2.1 since this definition is dependent on the MDAC version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:403"/>
        <criterion comment="the version of msadco.dll is less than 2.12.5118.0" negate="false" test_ref="oval:org.mitre.oval:tst:402"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:357" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3568" version="1" class="vulnerability">
      <metadata>
        <title>OLE Component Input Validation Vulnerability (Server / XP 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>OLE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0044"/>
        <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-02-16T12:00:00.000-04:00" comment="Added registry check to include three platforms">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-02-18T10:39:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of ole32.dll is less than 5.2.3790.250" negate="false" test_ref="oval:org.mitre.oval:tst:1486"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
        <criteria operator="OR" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3567" version="1" class="vulnerability">
      <metadata>
        <title>Patches Disable Basic Security Module Auditing Functionality</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Basic Security Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1358" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1358"/>
        <description>The patches (1) 114332-08 and (2) 114929-06 for Sun Solaris 9 disable the auditing functionality of the Basic Security Module (BSM), which allows attackers to avoid having their activity logged.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Patch 114332-08 installed" negate="false" test_ref="oval:org.mitre.oval:tst:406"/>
          <criterion comment="Patch 114332-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/system has BSM enabled" negate="false" test_ref="oval:org.mitre.oval:tst:404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:356" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3556" version="1" class="vulnerability">
      <metadata>
        <title>.NET Framework v1.1 Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MDAC 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0847"/>
        <description>The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .aspx files in restricted directories via a request containing a (1) "\" (backslash) or (2) "%5C" (encoded backslash), aka "Path Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Is the .NET Framework 1.1 installed" negate="false" test_ref="oval:org.mitre.oval:tst:412"/>
        <criteria operator="OR" comment="A vulnerable version of .NET Framework v1.1 is installed.">
          <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.1 (SP 1) is installed.">
            <criterion comment="Is Service Pack 1 for .NET Framework 1.1 installed" negate="false" test_ref="oval:org.mitre.oval:tst:411"/>
            <criterion comment="the version of System.web.dll is less than 1.1.4322.2037" negate="false" test_ref="oval:org.mitre.oval:tst:410"/>
            <criterion comment="Is the KB886903 patch installed for .NET Framework v1.1 sp 1?" negate="true" test_ref="oval:org.mitre.oval:tst:409"/>
          </criteria>
          <criteria operator="AND" comment="A vulnerable version of .NET Framework v1.1 (Gold) is installed.">
            <criterion comment="Is Service Pack 1 for .NET Framework 1.1 installed" negate="true" test_ref="oval:org.mitre.oval:tst:411"/>
            <criterion comment="the version of System.web.dll is less than 1.1.4322.1085" negate="false" test_ref="oval:org.mitre.oval:tst:408"/>
            <criterion comment="Is the KB886904 patch installed for .NET Framework v1.1 Gold?" negate="true" test_ref="oval:org.mitre.oval:tst:407"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3544" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP CSRSS Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Client Server Runtime System (CSRSS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
        <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
        <criteria operator="AND" comment="Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634">
          <criteria operator="OR" comment="Windows No Service Pack or Service Pack 1">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
          <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" negate="false" test_ref="oval:org.mitre.oval:tst:413"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:354" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <description>An SCLT_INCOMPLETE error was blocking receipt of proper READY status from the array.  A timer was changed to allow array to reach full READY before SCSI response is tested.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.771-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.10" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.10" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.10" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.10" negate="false" test_ref="oval:org.mitre.oval:tst:3540"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.10" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.10" negate="false" test_ref="oval:org.mitre.oval:tst:3540"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ARRAY-MGMT or OS-Core.ADMN-ENG-A-MAN (11.00/11.10)" negate="false">
          <criterion comment="OS-Core.ARRAY-MGMT (B.11.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3969"/>
          <criterion comment="OS-Core.ADMN-ENG-A-MAN (B.11.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3707"/>
          <criterion comment="OS-Core.ARRAY-MGMT (B.11.10) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3449"/>
          <criterion comment="OS-Core.ADMN-ENG-A-MAN (B.11.10) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3377"/>
        </criteria>
        <criterion comment="Patch PHCO_23262 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3533" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645. Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criterion comment="the version of shell32.dll is less than 6.0.2600.151" negate="false" test_ref="oval:org.mitre.oval:tst:414"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:353" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp4 installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:352" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp3 installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3514" version="1" class="vulnerability">
      <metadata>
        <title>IE .chm Directory Traversal Windows Server 2003 Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1041"/>
        <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:351" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Function Pointer Override Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0815" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0815"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and read arbitrary files by (1) modifying the createTextRange method and using CreateLink, as demonstrated using LinkillerSaveRef, LinkillerJPU, and Linkiller, or (2) modifying the createRange method and using the FIND dialog to select text, as demonstrated using Findeath, aka the "Function Pointer Override Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of having IE 5.01 sp2 installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3508" version="2" class="vulnerability">
      <metadata>
        <title>WinXP Large Window Size TCP RST Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230"/>
        <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:54.577-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
        <criteria operator="OR" comment="A vulnerable version of tcpip.sys is installed.">
          <criteria operator="AND" comment="Service Pack 1 is installed and tcpip.sys is less than 5.1.2600.1693">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1693" negate="false" test_ref="oval:org.mitre.oval:tst:776"/>
          </criteria>
          <criteria operator="AND" comment="Service Pack 2 is installed and tcpip.sys is less than 5.1.2600.2685">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2685" negate="false" test_ref="oval:org.mitre.oval:tst:775"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3505" version="1" class="vulnerability">
      <metadata>
        <title>sshd Log Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>sshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1357"/>
        <description>The Secure Shell (SSH) Daemon (SSHD) in Sun Solaris 9 does not properly log IP addresses when SSHD is configured with the ListenAddress as 0.0.0.0, which makes it easier for remote attackers to hide the source of their activities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Secure Shell Server - Usr (SUNWsshdu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:417"/>
          <criterion comment="Patch 113273-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:416"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/ssh/sshd_config has 0.0.0.0 as ListenAddress" negate="false" test_ref="oval:org.mitre.oval:tst:415"/>
          <criterion comment="sshd running" negate="false" test_ref="oval:org.mitre.oval:tst:484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:350" version="1" class="vulnerability">
      <metadata>
        <title>PEAR XML_RPC PHP Code Execution Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>php</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1921" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1921"/>
        <description>Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7) phpWebSite, (8) Ampache, and others, allows remote attackers to execute arbitrary PHP code via an XML file, which is not properly sanitized before being used in an eval statement.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="php RPM prior to  0:4.3.2-24.ent" negate="false" test_ref="oval:org.mitre.oval:tst:2687"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/httpd/conf.d/php.conf exists" negate="false" test_ref="oval:org.mitre.oval:tst:2684"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:35" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS FTP Connection Status Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>FTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0073"/>
        <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3496" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT IE HTML Help ActiveX control Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>HTML Help ActiveX Control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1043"/>
        <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:54.357-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false" test_ref="oval:org.mitre.oval:tst:971"/>
          <criterion comment="the patch Q890175 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:418"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:349" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 (Server 2003) ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows Server 2003.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit, Version 2003 and Windows Server 2003 64-Bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.94" negate="false" test_ref="oval:org.mitre.oval:tst:2686"/>
          <criterion comment="the patch q824145 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2685"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3483" version="2" class="vulnerability">
      <metadata>
        <title>NetBT Name Service Information Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>NetBT Name Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0661" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0661"/>
        <description>The NetBT Name Service (NBNS) for NetBIOS in Windows NT 4.0, 2000, XP, and Server 2003 may include random memory in a response to a NBNS query, which could allow remote attackers to obtain sensitive information.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-19T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2004-07-20T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:21.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="Patch WindowsXP-KB824105-x86-ENU.exe installed on XP or XP SP1" negate="true">
          <criterion comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed" negate="false" test_ref="oval:org.mitre.oval:tst:422"/>
          <criterion comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed on XP SP1" negate="false" test_ref="oval:org.mitre.oval:tst:421"/>
        </criteria>
        <criteria operator="OR" comment="XP SP1 or Pre SP1 with correct netbt.sys version">
          <criteria operator="AND" comment="Pre Service Pack XP and netbt.sys is less than 5.1.2600.117">
            <criterion comment="the version of netbt.sys is less than 5.1.2600.117" negate="false" test_ref="oval:org.mitre.oval:tst:420"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
          <criteria operator="AND" comment="XP SP1 and netbt.sys is less than 5.1.2600.1243">
            <criterion comment="the version of netbt.sys is less than 5.1.2600.1243" negate="false" test_ref="oval:org.mitre.oval:tst:419"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:348" version="2">
      <metadata>
        <title>Microsoft PowerPoint Malformed Records Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3449" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3449" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2006-1540, aka "Microsoft PowerPoint Malformed Record Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:21.369-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:38.809-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="PowerPoint 2000" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8948" test_ref="oval:org.mitre.oval:tst:16"/>
        </criteria>
        <criteria comment="PowerPoint 2002" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6811.0" test_ref="oval:org.mitre.oval:tst:17"/>
        </criteria>
        <criteria comment="PowerPoint 2003" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8036.0" test_ref="oval:org.mitre.oval:tst:110"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3464" version="1" class="vulnerability">
      <metadata>
        <title>IE AbusiveParent Vulnerability (32-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
        <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed  with service pack 2 (or earlier)">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
        </criteria>
        <criterion comment="the version of dhtmled.ocx is less than 6.1.0.9232" negate="false" test_ref="oval:org.mitre.oval:tst:427"/>
        <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3460" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server 2003 (Windows Server 2003, 64-Bit Edition) Routing Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>SMTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0840"/>
        <description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T10:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="The version of smtpsvc.dll is less than 6.0.3790.211" negate="false" test_ref="oval:org.mitre.oval:tst:558"/>
          <criterion comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" negate="true" test_ref="oval:org.mitre.oval:tst:428"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3054"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:346" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003,SP1 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.636-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.231-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4033"/>
        <criterion comment="SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3342"/>
        <criterion comment="rdpwd.sys is less than 5.2.3790.2465" negate="false" test_ref="oval:org.mitre.oval:tst:3760"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3458" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Blind Connection Reset Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:54.175-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3456" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (32-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.2800.1643" negate="false" test_ref="oval:org.mitre.oval:tst:606"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2657"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:345" version="1" class="vulnerability">
      <metadata>
        <title>shtool Race Condition</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>php</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1751" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1751"/>
        <description>Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="php RPM prior to  0:4.3.2-24.ent" negate="false" test_ref="oval:org.mitre.oval:tst:2687"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/tmp is writable by everyone" negate="false" test_ref="oval:org.mitre.oval:tst:2856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:344" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 6 sp1 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-01-29T12:00:00.000-04:00" comment="Added Windows XP 64-bit to the list of affected platforms">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1276" negate="false" test_ref="oval:org.mitre.oval:tst:2688"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:343" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for specific Windows operating systems.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.5 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4934.1600" negate="false" test_ref="oval:org.mitre.oval:tst:2689"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3428" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Task Scheduler Stack Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Task Scheduler</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0212"/>
        <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of mstask.dll is less than 4.71.2195.6920" negate="false" test_ref="oval:org.mitre.oval:tst:429"/>
        <criterion comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:720"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:342" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp4 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp4 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3810.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2690"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3416" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Table Conversion Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Replaced all criteria. 1) Included all Win2k versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of wordpad.exe is less than 5.0.2195.6991" negate="false" test_ref="oval:org.mitre.oval:tst:1047"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:341" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp3 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp3 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3400" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in Solaris ping Daemon</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1352"/>
        <description>Buffer overflow in the ping daemon of Sun Solaris 7 through 9 may allow local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 OR Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 and Solaris Basic IP Commands (SUNWbip) installed">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="Solaris Basic IP Commands (SUNWbip) installed" negate="false" test_ref="oval:org.mitre.oval:tst:433"/>
          </criteria>
        </criteria>
        <criterion comment="Patch 118313-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:432"/>
        <criterion comment="Patch 116986-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:431"/>
        <criterion comment="Patch 116774-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:430"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:340" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 ComboBox/ListBox GUI Widget User32.dll Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0659"/>
        <description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Added the patch KB891711 (from MS05-002) which supercedes the previous patch">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-28T09:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T07:32:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:22:00.000-04:00" comment="modified wft-285 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\user32.dll version is less than 5.0.2195.6799" negate="false" test_ref="oval:org.mitre.oval:tst:2691"/>
          <criterion comment="the patch kb824141 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2808"/>
          <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the utility manager Service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2806"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:34" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 whodo Buffer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>whodo</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1076" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1076"/>
        <description>Buffer overflow in whodo in Solaris SunOS 5.5.1 through 5.8 allows local users to execute arbitrary code via a long (1) SOR or (2) CFIME environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File whodo exists" negate="false" test_ref="oval:org.mitre.oval:tst:3043"/>
          <criterion comment="Patch 111600-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3042"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File whodo SUID and executable">
            <criterion comment="File whodo SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3041"/>
            <criterion comment="File whodo SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3040"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3391" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP SMB Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0345"/>
        <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2932"/>
        <criteria operator="OR" comment="XP SP1 or pre SP1 with version check on Srv.sys">
          <criteria operator="AND" comment="XP Pre- SP1 with Srv.sys is less than 5.1.2600.112">
            <criterion comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.112" negate="false" test_ref="oval:org.mitre.oval:tst:435"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
          <criteria operator="AND" comment="XP SP1 and srv.sys is less than 5.1.2600.1193">
            <criterion comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.1193" negate="false" test_ref="oval:org.mitre.oval:tst:434"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:339" version="2">
      <metadata>
        <title>Windows Shell Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3730" source="CVE"/>
        <description>Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:36.841-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:45.994-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Comctl32.dll is less than 5.81.3900.7109" test_ref="oval:org.mitre.oval:tst:135"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Comctl32.dll is less than 5.82.2800.1891" test_ref="oval:org.mitre.oval:tst:91"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Comctl32.dll is less than 5.82.2900.2982" test_ref="oval:org.mitre.oval:tst:54"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Comctl32.dll is less than 5.82.3790.2778" test_ref="oval:org.mitre.oval:tst:58"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Comctl32.dll is less than 5.82.3790.583" test_ref="oval:org.mitre.oval:tst:59"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Comctl32.dll is less than 5.82.3790.2778" test_ref="oval:org.mitre.oval:tst:58"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3386" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-04T01:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-06T12:57:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of shell32.dll is less than 5.0.3900.6922" negate="false" test_ref="oval:org.mitre.oval:tst:436"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3376" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6.0 (WinXP) Malformed Email Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0215"/>
        <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-26T08:07:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-26T08:14:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-13T11:40:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Outlook Express 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1353"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2742.200" negate="false" test_ref="oval:org.mitre.oval:tst:437"/>
          <criterion comment="the patch kb823353 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:668"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="all users have the preview pane disabled" negate="false" test_ref="oval:org.mitre.oval:tst:667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3372" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003, IE v6,SP1 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:336" version="2" class="vulnerability">
      <metadata>
        <title>MS Word 2000 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-19 - wft-19 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:21.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8216" negate="false" test_ref="oval:org.mitre.oval:tst:2692"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3355" version="2" class="vulnerability">
      <metadata>
        <title>LoadImage Cursor and Icon Format Handling Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Cursor and Icon Formatting</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1049"/>
        <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:53.630-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of user32.dll is less than 4.0.1381.7342" negate="false" test_ref="oval:org.mitre.oval:tst:2400"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:335" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 ExecCommand Cross Domain Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0814" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0814"/>
        <description>Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-21T12:00:00.000-04:00" comment="Removed the test for Windows 2000 sp2 installed.  This is not part of the vulnerability definition.  Instead, it is a pre-requisite of installing the IE 5.01 sp2 patch.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls and active scripting are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3523.1700" negate="false" test_ref="oval:org.mitre.oval:tst:2693"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:334" version="1" class="vulnerability">
      <metadata>
        <title>Windows NNTP Memory Leak</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0543" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0543"/>
        <description>Memory leak in NNTP service in Windows NT 4.0 and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed posts.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of nntpsvc.dll is less than 5.0.2195.3881" negate="false" test_ref="oval:org.mitre.oval:tst:2695"/>
          <criterion comment="Patch Q303984 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2694"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3333" version="1" class="vulnerability">
      <metadata>
        <title>Office XP, SP3 WordPerfect Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XP SP3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0573"/>
        <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-09-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-489 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office XP Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1592"/>
        <criterion comment="the version of msconv97.dll is less than 2003.1100.6252.0" negate="false" test_ref="oval:org.mitre.oval:tst:492"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:333" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Domain Restriction Bypass Cross-Frame Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1217"/>
        <description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame> and &lt;iframe> domain restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3325" version="1" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (32-bit XP, SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of lsasrv.dll is less than 5.1.2600.1597" negate="false" test_ref="oval:org.mitre.oval:tst:631"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3322" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos 5 Double-free Vulnerability in krb5_rd_cred Function</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0643" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0643"/>
        <description>Double-free vulnerability in the krb5_rd_cred function for MIT Kerberos 5 (krb5) 1.3.1 and earlier may allow local users to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed kerberos unknown test to solaris file contents test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:616"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3320" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Visio Pro 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visio Professional 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-495 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB838345.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Visio Professional 2003 is Installed" negate="false" test_ref="oval:org.mitre.oval:tst:439"/>
        <criterion comment="the version of gdiplus.dll is less than 6.0.3264.0" negate="false" test_ref="oval:org.mitre.oval:tst:438"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3318" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" negate="false" test_ref="oval:org.mitre.oval:tst:1329"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" negate="false" test_ref="oval:org.mitre.oval:tst:1328"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3312" version="1" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (Server 2003/64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false" test_ref="oval:org.mitre.oval:tst:842"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3311" version="1" class="vulnerability">
      <metadata>
        <title>Office 2003 WordPerfect Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0573"/>
        <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-13T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-489 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-516 - wrt-516 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:487"/>
        <criterion comment="the version of msconv97.dll is less than 2003.1100.6252.0" negate="false" test_ref="oval:org.mitre.oval:tst:492"/>
        <criterion comment="Patch KB873378 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:440"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3310" version="2" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Font Conversion Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:53.395-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 4.0.1381.7312" negate="false" test_ref="oval:org.mitre.oval:tst:441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:331" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Workstation Service Logging Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Windows Workstation Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0812" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0812"/>
        <description>Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers to execute arbitrary code via RPC calls that cause long entries to be written to a debug log file ("NetSetup.LOG"), as demonstrated using the NetAddAlternateComputerName API.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-03-08T12:00:00.000-04:00" comment="Added 64-bit edition support to this definition allowing us to deprecated OVAL332">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:26:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of wkssvc.dll exists">
            <criteria operator="AND" comment="no service pack is installed and wkssvc.dll is less than 5.1.2600.120">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of wkssvc.dll is less than 5.1.2600.120" negate="false" test_ref="oval:org.mitre.oval:tst:2736"/>
            </criteria>
            <criteria operator="AND" comment="service pack 1 is installed and wkssvc.dll is less than 5.1.2600.1301">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of wkssvc.dll is less than 5.1.2600.1301" negate="false" test_ref="oval:org.mitre.oval:tst:2735"/>
            </criteria>
          </criteria>
          <criterion comment="the patch q828035 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2796"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the workstation service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2696"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:330" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mscms.dll is less than 5.1.2600.2709" negate="false" test_ref="oval:org.mitre.oval:tst:2698"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:33" version="1" class="vulnerability">
      <metadata>
        <title>Sun Solaris 7 XSun Color Database File Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0158"/>
        <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File Xsun exists" negate="false" test_ref="oval:org.mitre.oval:tst:3109"/>
          <criterion comment="Patch 108376-38 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3044"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Xsun SGID and executable">
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3107"/>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:328" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel /proc/self setuid Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0501" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0501"/>
        <description>The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:327" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel execve Read Acces to Restricted File Descriptors</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0476"/>
        <description>The execve system call in Linux 2.4.x records the file descriptor of the executable process in the file table of the calling process, which allows local users to gain read access to restricted file descriptors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3250" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird POP3 SendUidl Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0757" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0757"/>
        <description>Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3242" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T08:03:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criteria operator="OR" comment="a vulnerable version of netdde.exe exists">
          <criterion comment="the version of netdde.exe is less than 5.1.2600.1567" negate="false" test_ref="oval:org.mitre.oval:tst:445"/>
          <criterion comment="the 64-bit WOW version of netdde.exe is less than 5.1.2600.1567" negate="false" test_ref="oval:org.mitre.oval:tst:444"/>
        </criteria>
        <criteria operator="OR" comment="a vulnerable version of nddenb32.dll exists">
          <criterion comment="the version of nddenb32.dll is less than 5.1.2600.1555" negate="false" test_ref="oval:org.mitre.oval:tst:443"/>
          <criterion comment="the 64-bit WOW version of nddenb32.dll is less than 5.1.2600.1555" negate="false" test_ref="oval:org.mitre.oval:tst:442"/>
        </criteria>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3220" version="1" class="vulnerability">
      <metadata>
        <title>LoadImage Cursor and Icon Format Handling Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Cursor and Icon Formatting</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1049"/>
        <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of user32.dll is less than 5.2.3790.245" negate="false" test_ref="oval:org.mitre.oval:tst:512"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
        <criteria operator="OR" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:322" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false" test_ref="oval:org.mitre.oval:tst:2762"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3216" version="1" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.0.2195.7017" negate="false" test_ref="oval:org.mitre.oval:tst:446"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:321" version="1" class="vulnerability">
      <metadata>
        <title>Windows Media Player Directory Traversal</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player for Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0228"/>
        <description>Directory traversal vulnerability in Microsoft Windows Media Player 7.1 and Windows Media Player for Windows XP allows remote attackers to execute arbitrary code via a skins file with a URL containing hex-encoded backslash characters (%5C) that causes an executable to be placed in an arbitrary location.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player for Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2727"/>
        <criterion comment="the version of wmplayer.exe is less than 8.0.0.4490" negate="false" test_ref="oval:org.mitre.oval:tst:2700"/>
        <criterion comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2699"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3203" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Hyperlink Object Library Unchecked Buffer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Hyperlink Object Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0057"/>
        <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-11T09:34:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of hlink.dll exists on Server 2003">
          <criterion comment="machine has followed the GDR update path and hlink.dll is less than 5.2.3790.225" negate="false" test_ref="oval:org.mitre.oval:tst:448"/>
          <criterion comment="machine has followed the QFE update path and hlink.dll is less than 5.2.3790.227" negate="false" test_ref="oval:org.mitre.oval:tst:447"/>
        </criteria>
        <criterion comment="the patch kb888113 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2398"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:32" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Forced Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0026"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3091"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3196" version="1" class="vulnerability">
      <metadata>
        <title>IE6.0,SP2 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-159 - unchecked value">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false" test_ref="oval:org.mitre.oval:tst:2402"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:319" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT getCanonicalPath Heap Corruption Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows NT 4.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0525" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0525"/>
        <description>The getCanonicalPath function in Windows NT 4.0 may free memory that it does not own and cause heap corruption, which allows attackers to cause a denial of service (crash) via requests that cause a long file name to be passed to getCanonicalPath, as demonstrated on the IBM JVM using a long string to the java.io.getCanonicalPath Java method.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Workstation" negate="true" test_ref="oval:org.mitre.oval:tst:2703"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of kernel32.dll is less than 4.0.1381.7224" negate="false" test_ref="oval:org.mitre.oval:tst:2702"/>
        <criterion comment="Patch Q823803 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2701"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:318" version="2">
      <metadata>
        <title>Folder GUID Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3281" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3281" source="CVE"/>
        <description>Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka "Folder GUID Code Execution Vulnerability."  NOTE: directory traversal sequences were used in the original exploit, although their role is not clear.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:20.777-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:38.214-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of shell32.dll is less than 5.0.3900.7105" test_ref="oval:org.mitre.oval:tst:129"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of shell32.dll is less than 6.0.2800.1873" test_ref="oval:org.mitre.oval:tst:199"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of shell32.dll is less than 6.0.2900.2951" test_ref="oval:org.mitre.oval:tst:160"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.2746" test_ref="oval:org.mitre.oval:tst:12"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.559" test_ref="oval:org.mitre.oval:tst:14"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.2746" test_ref="oval:org.mitre.oval:tst:12"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3179" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT HtmlHelp Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0201"/>
        <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Internet Explorer 5.5 SP2 or Internet Explorer 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
            <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
            <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          </criteria>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3161" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP VDM Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0208"/>
        <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T09:58:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="the version of vdmdbg.dll is less than 5.1.2600.1560" negate="false" test_ref="oval:org.mitre.oval:tst:681"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:316" version="1" class="vulnerability">
      <metadata>
        <title>MS SQL Server Bulk Insert Procedure Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0641" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0641"/>
        <description>Buffer overflow in bulk insert procedure of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows attackers with database administration privileges to execute arbitrary code via a long filename in the BULK INSERT query.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-237 - literal string corrected">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-65 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-66 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-67 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-68 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-69 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-278 - wft-278 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-58 - wft-58 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.650.0" negate="false" test_ref="oval:org.mitre.oval:tst:2718"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2925"/>
        <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2924"/>
        <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2923"/>
        <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2922"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2921"/>
        <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false" test_ref="oval:org.mitre.oval:tst:2920"/>
        <criterion comment="the version of impprov.dll is less than 2000.80.650.0" negate="false" test_ref="oval:org.mitre.oval:tst:2704"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3157" version="1" class="vulnerability">
      <metadata>
        <title>IE6 (for XP,SP2) Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2627" negate="false" test_ref="oval:org.mitre.oval:tst:768"/>
          <criterion comment="the patch kb890923  is installed (XP SP2 Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:767"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3145" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kernel Debugger-based Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" negate="false" test_ref="oval:org.mitre.oval:tst:449"/>
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3138" version="1" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-07T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-24T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="modified wrt-44 -">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-169 - Change to access dll via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the patch Windows 2003 kb873339 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:451"/>
          <criterion comment="the version of hypertrm.dll is less than 5.2.3790.233" negate="false" test_ref="oval:org.mitre.oval:tst:450"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3137" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Heap Memory Corruption Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T08:33:00.000-04:00" comment="modified wrt-158 - removed note">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-158 - removed value to check against">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false" test_ref="oval:org.mitre.oval:tst:978"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3134" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla CA Certificate DoS</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0758"/>
        <description>Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allows remote attackers to cause a denial of service to SSL pages because the malicious certificate is treated as invalid.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3120" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Unchecked Buffer in NetDDE (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T04:17:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp5 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of netdde.exe is less than 5.0.2195.6952" negate="false" test_ref="oval:org.mitre.oval:tst:453"/>
        <criterion comment="the version of nddenb32.dll is less than 5.0.2195.6922" negate="false" test_ref="oval:org.mitre.oval:tst:452"/>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:312" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00622788"/>
        <description>An undisclosed vulnerability has been identified in swagentd that could potentially be exploited remotely by an unauthenticated attacker to cause swagentd to abort.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.485-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:53.044-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.04 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_30302 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_30302 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3559"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_30006 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_30006 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3243"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:311" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel Reuse Flag Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0464" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0464"/>
        <description>The RPC code in Linux kernel 2.4 sets the reuse flag when sockets are created, which could allow local users to bind to UDP ports that are used by privileged services such as nfsd.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3100" version="1" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE6 for Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:44:00.000-04:00" comment="modified wft-594 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.279" negate="false" test_ref="oval:org.mitre.oval:tst:515"/>
          <criterion comment="the patch kb890923 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:514"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:310" version="2">
      <metadata>
        <title>Microsoft .NET Framework 2.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft .NET Framework 2.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:20.530-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:37.968-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="The .NET Framework 2.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:190"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:31" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8/9 cachefsd Heap Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0033"/>
        <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Updated to include Solaris 9 and Solaris 9 patch info">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:24:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criterion comment="Patch 110896-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3052"/>
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 114008-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3050"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3097" version="1" class="vulnerability">
      <metadata>
        <title>LoadImage Cursor and Icon Format Handling Vulnerability (Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Cursor and Icon Formatting</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1049"/>
        <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="the version of user32.dll is less than 4.0.1381.33630" negate="false" test_ref="oval:org.mitre.oval:tst:454"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3095" version="1" class="vulnerability">
      <metadata>
        <title>WinXP Explorer Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Explorer.exe</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0306" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0306"/>
        <description>Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-19T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Patch KB821557 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:457"/>
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="Version check for XP SP1 and XP no service pack for shell32.dll">
          <criteria operator="AND" comment="XP Service Pack 1 and version of Shell32.dll is less than 6.0.2800.1233">
            <criterion comment="the version of shell32.dll is less than 6.0.2800.1233" negate="false" test_ref="oval:org.mitre.oval:tst:456"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="XP no Service Pack installed and version of Shell32.dll is less than 6.0.2600.115">
            <criterion comment="the version of shell32.dll is less than 6.0.2600.115" negate="false" test_ref="oval:org.mitre.oval:tst:455"/>
            <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:969"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:309" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel execve Race Condition Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0462" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0462"/>
        <description>A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3082" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Visio Pro 2002)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visio Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-496 - corrected registry path check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB831932.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Visio Professional 2002 with service pack 2" negate="false" test_ref="oval:org.mitre.oval:tst:481"/>
        <criterion comment="the version of mso.dll is less than 10.0.6714.0" negate="false" test_ref="oval:org.mitre.oval:tst:463"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:308" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft FrontPage Server Extensions 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp4awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T10:51:00.000-04:00" comment="modified wft-12 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the version of shtml.dll is less than 4.00.02.7523" negate="false" test_ref="oval:org.mitre.oval:tst:2708"/>
          <criterion comment="the patch q810217 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2707"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2706"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3078" version="1" class="vulnerability">
      <metadata>
        <title>CDE AddSuLog Function Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0691" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0691"/>
        <description>Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a long user name.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" negate="false" test_ref="oval:org.mitre.oval:tst:459"/>
        <criterion comment="Patch 108219-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:458"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3071" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:52.848-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criteria operator="OR" comment="a vulnerable version of grpconv.exe exists on NT">
          <criteria operator="AND" comment="NT Server and grpconv.exe less than 4.0.1381.7286">
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
            <criterion comment="the version of grpconv.exe (system32) is less than 4.0.1381.7286" negate="false" test_ref="oval:org.mitre.oval:tst:461"/>
          </criteria>
          <criteria operator="AND" comment="NT Terminal Server and grpconv.exe less than 4.0.1381.33577">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of grpconv.exe (system32) is less than 4.0.1381.33577" negate="false" test_ref="oval:org.mitre.oval:tst:460"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:307" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0615" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0615"/>
        <description>Cross-site scripting (XSS) vulnerability in start_form() of CGI.pm allows remote attackers to insert web script via a URL that is fed into the form's action parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.271-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.795-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="Solaris 8 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101426 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119449-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3644"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101426 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119450-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3771"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3060" version="1" class="vulnerability">
      <metadata>
        <title>IE6 for Server 2003 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T08:52:00.000-04:00" comment="modified wrt-158 - removed note">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-158 - removed value to check against">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false" test_ref="oval:org.mitre.oval:tst:978"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:306" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3055" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Named Pipe Vulnerability (64-bit architecture)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0051"/>
        <description>The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T09:34:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of srvsvc.dll is less than 5.1.2600.1613" negate="false" test_ref="oval:org.mitre.oval:tst:462"/>
        <criterion comment="the patch kb888302 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:559"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:304" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Linux Kernel Serial Link Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0461" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0461"/>
        <description>/proc/tty/driver/serial in Linux 2.4.x reveals the exact number of characters used in serial links, which could allow local users to obtain potentially sensitive information such as the length of passwords.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-19.9" negate="false" test_ref="oval:org.mitre.oval:tst:2709"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3038" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Project 2002,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Project Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T12:00:00.000-04:00" comment="Changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-496 - corrected registry path check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB831931.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Project Professional 2002 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:555"/>
        <criterion comment="the version of mso.dll is less than 10.0.6714.0" negate="false" test_ref="oval:org.mitre.oval:tst:463"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:303" version="1" class="vulnerability">
      <metadata>
        <title>SQL Server LPC Port Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0232" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0232"/>
        <description>Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-72 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-70 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:41:00.000-04:00" comment="modified wft-73 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:51:00.000-04:00" comment="modified wft-78 - wft-78 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:01:00.000-04:00" comment="modified wft-79 - wft-79 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:31:00.000-04:00" comment="modified wft-51 - wft-51 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:32:00.000-04:00" comment="modified wft-52 - wft-52 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:33:00.000-04:00" comment="modified wft-53 - wft-53 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:34:00.000-04:00" comment="modified wft-54 - wft-54 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:51:00.000-04:00" comment="modified wft-60 - wft-60 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:23:00.000-04:00" comment="modified wft-70 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:24:00.000-04:00" comment="modified wft-72 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:25:00.000-04:00" comment="modified wft-73 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File console.exe version3 is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2780"/>
        <criterion comment="the version of dbmslpcn.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2713"/>
        <criterion comment="File sqlmap70.dll version3 is less than 2000.80.811.0" negate="false" test_ref="oval:org.mitre.oval:tst:2778"/>
        <criterion comment="File sqlrepss.dll version3 is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2777"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2776"/>
        <criterion comment="the version of ssmslpcn.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2775"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2774"/>
        <criterion comment="the version of ssnmpn70.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2773"/>
        <criterion comment="the version of ums.dll is less than 2000.80.816.0" negate="false" test_ref="oval:org.mitre.oval:tst:2772"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.800.0" negate="false" test_ref="oval:org.mitre.oval:tst:2771"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.778.0" negate="false" test_ref="oval:org.mitre.oval:tst:2770"/>
        <criterion comment="the version of msgprox.dll is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2712"/>
        <criterion comment="the version of replprov.dll is less than 2000.80.798.0" negate="false" test_ref="oval:org.mitre.oval:tst:2768"/>
        <criterion comment="the version of replrec.dll is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2711"/>
        <criterion comment="the version of sqlvdi.dll is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2710"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3006" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
            <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
            <criterion comment="the patch kb834707(wildcard*) is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:977"/>
          </criteria>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:30" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft SMTP Malformed BDAT Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0055"/>
        <description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-30T12:00:00.000-04:00" comment="Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" negate="false" test_ref="oval:org.mitre.oval:tst:3056"/>
          <criterion comment="Patch Q313450" negate="true" test_ref="oval:org.mitre.oval:tst:3055"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3054"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:3" version="2">
      <metadata>
        <title>SMB Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-1315" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1314" source="CVE"/>
        <description>The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:20.234-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:37.531-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of srv.sys is less than 5.0.2195.7087" negate="false" test_ref="oval:org.mitre.oval:tst:64"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.1832" negate="false" test_ref="oval:org.mitre.oval:tst:23"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of srv.sys is less than 5.1.2600.2893" negate="false" test_ref="oval:org.mitre.oval:tst:127"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" negate="false" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.526" negate="false" test_ref="oval:org.mitre.oval:tst:97"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of srv.sys is less than 5.2.3790.2691" negate="false" test_ref="oval:org.mitre.oval:tst:161"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:299" version="1" class="vulnerability">
      <metadata>
        <title>SQL Server Named Pipe Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0231"/>
        <description>Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-55 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-72 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-70 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-73 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-78 - wft-78 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:35:00.000-04:00" comment="modified wft-79 - wft-79 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:36:00.000-04:00" comment="modified wft-51 - wft-51 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:37:00.000-04:00" comment="modified wft-52 - wft-52 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:38:00.000-04:00" comment="modified wft-53 - wft-53 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:39:00.000-04:00" comment="modified wft-54 - wft-54 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:40:00.000-04:00" comment="modified wft-60 - wft-60 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T01:23:00.000-04:00" comment="modified wft-70 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:24:00.000-04:00" comment="modified wft-72 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:25:00.000-04:00" comment="modified wft-73 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File console.exe version3 is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2780"/>
        <criterion comment="the version of dbmslpcn.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2713"/>
        <criterion comment="File sqlmap70.dll version3 is less than 2000.80.811.0" negate="false" test_ref="oval:org.mitre.oval:tst:2778"/>
        <criterion comment="File sqlrepss.dll version3 is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2777"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2776"/>
        <criterion comment="the version of ssmslpcn.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2775"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2774"/>
        <criterion comment="the version of ssnmpn70.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2773"/>
        <criterion comment="the version of ums.dll is less than 2000.80.816.0" negate="false" test_ref="oval:org.mitre.oval:tst:2772"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.800.0" negate="false" test_ref="oval:org.mitre.oval:tst:2771"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.778.0" negate="false" test_ref="oval:org.mitre.oval:tst:2770"/>
        <criterion comment="the version of msgprox.dll is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2712"/>
        <criterion comment="the version of replprov.dll is less than 2000.80.798.0" negate="false" test_ref="oval:org.mitre.oval:tst:2768"/>
        <criterion comment="the version of replrec.dll is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2711"/>
        <criterion comment="the version of sqlvdi.dll is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2710"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:298" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 SNMPv1 Trap Handling DoS and Privilege Escalation (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0013"/>
        <description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified date="2004-09-20T10:31:00.000-04:00" comment="Changed CAN-2002-0012 to CAN-2002-0013.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2975" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail prescan function Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0694"/>
        <description>The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Sendmail - user (SUNWsndmu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:587"/>
        <criterion comment="Patch 107684-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:466"/>
        <criterion comment="Patch 110615-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:465"/>
        <criterion comment="Patch 113575-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:464"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2972" version="1" class="vulnerability">
      <metadata>
        <title>Solaris TCP/IP Stack System Panic Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>TCP/IP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1355"/>
        <description>Unknown vulnerability in the TCP/IP stack for Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 116895-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:468"/>
        <criterion comment="Patch 117000-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:467"/>
        <criterion comment="Patch 112233-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:777"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:297" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>patchadd</product>
        </affected>
        <reference source="MISC" ref_id="http://sunsolve9.sun.com/search/document.do?assetkey=1-26-101666-1&amp;searchclause="/>
        <description>The patchadd facility for Solaris 10 fails to install T-patches.  Sun sometimes releases a T-patch as a temporary version of a patch prior to the final release of that patch.  While this flaw does not directly represent a vulnerability, it does prevent the timely application of some (possibly critical) updates.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:45.131-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.633-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101666 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119254-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3284"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101666 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119255-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3698"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2968" version="1" class="vulnerability">
      <metadata>
        <title>RPCSS DCOM Buffer Overflow (XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0528"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.109" negate="false" test_ref="oval:org.mitre.oval:tst:556"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2961" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Privilege Escalation Vulnerabilities in Linux Kernel</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0495"/>
        <description>Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-02T12:06:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-09-08T10:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0">
          <criterion comment="kernel rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:476"/>
          <criterion comment="kernel-hugemem rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:475"/>
          <criterion comment="kernel-smp rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:474"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:296" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0352"/>
        <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" negate="false" test_ref="oval:org.mitre.oval:tst:2714"/>
          <criterion comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3000"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2956" version="1" class="vulnerability">
      <metadata>
        <title>LoadImage Cursor and Icon Format Handling Vulnerability (XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Cursor and Icon Formatting</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1049"/>
        <description>Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format Handling Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.1.2600.1617" negate="false" test_ref="oval:org.mitre.oval:tst:1005"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2953" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 IE6.0 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-159 - unchecked value">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2604" negate="false" test_ref="oval:org.mitre.oval:tst:2402"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
            <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
            <criterion comment="the patch kb834707(wildcard*) is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:977"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:295" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel TCP/IP Fragment Reassembly Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0364"/>
        <description>The TCP/IP fragment reassembly handling in the Linux kernel 2.4 allows remote attackers to cause a denial of service (CPU consumption) via certain packets that cause a large number of hash table collisions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-18.9" negate="false" test_ref="oval:org.mitre.oval:tst:2721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:294" version="1" class="vulnerability">
      <metadata>
        <title>MS MDAC RDS Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for MDAC 2.6 since this definition is dependent on the MDAC version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of msadco.dll is less than 2.62.9119.1" negate="false" test_ref="oval:org.mitre.oval:tst:2716"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:292" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel mxcsr Code Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0248"/>
        <description>The mxcsr code in Linux kernel 2.4 allows attackers to modify CPU state registers via a malformed address.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-18.9" negate="false" test_ref="oval:org.mitre.oval:tst:2721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2919" version="1" class="vulnerability">
      <metadata>
        <title>Adobe Acrobat Reader .ETD Document Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Adobe Acrobat Reader</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1153"/>
        <description>Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an .ETD document containing format string specifiers in (1) title or (2) baseurl fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>iDEFENSE reports that deleting eBook.api from the plug_ins directory is a workaround.  See http://www.idefense.com/application/poi/display?id=163&amp;type=vulnerabilities</note>
      </notes>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="the software Adobe Acrobat Reader major version 6, minor version less than 3 is installed">
          <criterion comment="the software Adobe Acrobat Reader 6, major version 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:471"/>
          <criterion comment="the software Adobe Acrobat Reader 6, minor version less than 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:470"/>
        </criteria>
        <criterion comment="Adobe Acrobat Reader eBook.api plug-in software installed" negate="false" test_ref="oval:org.mitre.oval:tst:469"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2917" version="1" class="vulnerability">
      <metadata>
        <title>OLE Component Input Validation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0044"/>
        <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.0.2195.7021" negate="false" test_ref="oval:org.mitre.oval:tst:1109"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2915" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel Denial of Service Vulnerability via fsave and frstor Instructions</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0554"/>
        <description>Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-02T12:10:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-09-08T10:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0">
          <criterion comment="kernel rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:476"/>
          <criterion comment="kernel-hugemem rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:475"/>
          <criterion comment="kernel-smp rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:474"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:291" version="1" class="vulnerability">
      <metadata>
        <title>Unchecked Buffer in Password Encryption Procedure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0624" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0624"/>
        <description>Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, allows remote attackers to gain control of the database and execute arbitrary code via SQL Server Authentication, aka "Unchecked Buffer in Password Encryption Procedure."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-237 - literal string corrected">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-65 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-66 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-67 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-68 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-69 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-278 - wft-278 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
          <criterion comment="the version of sqlservr.exe is less than 2000.80.650.0" negate="false" test_ref="oval:org.mitre.oval:tst:2718"/>
          <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2925"/>
          <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2924"/>
          <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2923"/>
          <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2922"/>
          <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2921"/>
          <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false" test_ref="oval:org.mitre.oval:tst:2920"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Mixed Mode Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2975"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2906" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000, IE v5.01 CSS Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0842" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0842"/>
        <description>Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "&lt;STYLE>@;/*" string, possibly due to a missing comment terminator that may cause an invalid length to trigger a large memory copy operation, aka the "CSS Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T04:45:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:29" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Heap Overrun in HTR Chunked Encoding</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0364"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" negate="false" test_ref="oval:org.mitre.oval:tst:3059"/>
          <criterion comment="Patch Q321599 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3058"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ism.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2894" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-bit Gold) Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="the version of helpctr.exe is less than 5.1.2600.1515" negate="true" test_ref="oval:org.mitre.oval:tst:1321"/>
        <criterion comment="the version of shell32.dll is less than 6.0.3790.168" negate="false" test_ref="oval:org.mitre.oval:tst:551"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2892" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 COM Structured Storage Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0047"/>
        <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.1.2600.1619" negate="false" test_ref="oval:org.mitre.oval:tst:472"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2884" version="1" class="vulnerability">
      <metadata>
        <title>RPCSS DCOM Buffer Overflow (XP, SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0528"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1254" negate="false" test_ref="oval:org.mitre.oval:tst:708"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:287" version="1" class="vulnerability">
      <metadata>
        <title>Windows Media Player Buffer Overflow via ASF</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player for Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0719"/>
        <description>Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming Format (ASF) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player for Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2727"/>
        <criterion comment="the version of msdxm.ocx is less than 6.4.9.1121" negate="false" test_ref="oval:org.mitre.oval:tst:2720"/>
        <criterion comment="the version of dxmasf.dll is less than 6.4.9.1121" negate="false" test_ref="oval:org.mitre.oval:tst:2726"/>
        <criterion comment="Patch wm308567 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2719"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:285" version="2">
      <metadata>
        <title>XSLT Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services</product>
        </affected>
        <reference ref_id="CVE-2006-4686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4686" source="CVE"/>
        <description>Buffer overflow in the Extensible Stylesheet Language Transformations (XSLT) processing in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 allows remote attackers to execute arbitrary code via a crafted Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:36.018-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:44.869-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="The version of Msxml3.dll is less than 8.70.1113.0" negate="false" test_ref="oval:org.mitre.oval:tst:34"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
          <criterion comment="The version of Msxml4.dll is less than 4.20.9839.0" negate="false" test_ref="oval:org.mitre.oval:tst:72"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 5 is installed" definition_ref="oval:org.mitre.oval:def:493"/>
          <criterion comment="The version of Msxml5.dll is less than 5.10.2930.0" negate="false" test_ref="oval:org.mitre.oval:tst:87"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criterion comment="The version of Msxml6.dll is less than 6.0.3888.0" negate="false" test_ref="oval:org.mitre.oval:tst:32"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2847" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Windows POSIX Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>POSIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0210"/>
        <description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-24T23:42:00.000-04:00" comment="Fixed typo in obj:503, referenced by tst:609.  Was 'Subsystem' instead of 'SubSystems'.  Fix implemented by Matthew Wojcik of MITRE.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-09-23T20:21:00.000-04:00" comment="Replaced use of tst:3085 to test for Windows 2000 with extended inventory definition def:85.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-09-24T23:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-10T20:39:59.309-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <extend_definition comment="Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
          <criterion comment="the patch kb841872 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:612"/>
          <criterion comment="the version of psxss.exe is less than 5.0.2195.6929" negate="false" test_ref="oval:org.mitre.oval:tst:473"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="POSIX is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:609"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:284" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel TTY Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0247" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0247"/>
        <description>Unknown vulnerability in the TTY layer of the Linux kernel 2.4 allows attackers to cause a denial of service ("kernel oops").</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-26T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-18.9" negate="false" test_ref="oval:org.mitre.oval:tst:2721"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2830" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IE HTML Help ActiveX control Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1043"/>
        <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-03-01T12:00:00.000-04:00" comment="Removed software test to check for Windows service Packs">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <modified date="2005-03-24T12:00:00.000-04:00" comment="Added a configuration test to see if ActiveX controls are enabled.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false" test_ref="oval:org.mitre.oval:tst:971"/>
          <criterion comment="the patch kb890175 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:972"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2819" version="1" class="vulnerability">
      <metadata>
        <title>Denial of Service Vulnerability in Linux Kernel do_fork Function via CLONE_VM</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0427"/>
        <description>The do_fork function in Linux 2.4.x before 2.4.26, and 2.6.x before 2.6.6, does not properly decrement the mm_count counter when an error occurs after the mm_struct for a child process has been activated, which triggers a memory leak that allows local users to cause a denial of service (memory exhaustion) via the clone (CLONE_VM) system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-01T11:51:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-09-08T10:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="kernel, kernel-hugemem or kernel-smp rpm older than 2.4.21-15.0.2EL Epoch 0">
          <criterion comment="kernel rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:476"/>
          <criterion comment="kernel-hugemem rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:475"/>
          <criterion comment="kernel-smp rpm older than 2.4.21-15.0.2.EL Epoch 0" negate="false" test_ref="oval:org.mitre.oval:tst:474"/>
        </criteria>
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2817" version="1" class="vulnerability">
      <metadata>
        <title>IE for Server 2003 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T03:53:00.000-04:00" comment="modified wrt-158 - removed note">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-158 - removed value to check against">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false" test_ref="oval:org.mitre.oval:tst:978"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2816" version="1" class="vulnerability">
      <metadata>
        <title>XFS Dispatch() Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>fs.auto, xfs</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1317"/>
        <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="X Window System Font Server (SUNWxwfs) installed" negate="false" test_ref="oval:org.mitre.oval:tst:478"/>
          <criterion comment="Patch 113923-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:477"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains fs.auto" negate="false" test_ref="oval:org.mitre.oval:tst:2870"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:281" version="1" class="vulnerability">
      <metadata>
        <title>Cache Path Disclosure via Windows Media Player</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player for Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0372"/>
        <description>Microsoft Windows Media Player versions 6.4 and 7.1 and Media Player for Windows XP allow remote attackers to bypass Internet Explorer's (IE) security mechanisms and run code via an executable .wma media file with a license installation requirement stored in the IE cache, aka the "Cache Path Disclosure via Windows Media Player".</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player for Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2727"/>
        <criterion comment="the version of dxmasf.dll is less than 6.4.9.1121" negate="false" test_ref="oval:org.mitre.oval:tst:2726"/>
        <criterion comment="the version of msdxm.ocx is less than 6.4.9.1124" negate="false" test_ref="oval:org.mitre.oval:tst:2725"/>
        <criterion comment="the version of wmpcore.dll is less than 8.0.0.4482" negate="false" test_ref="oval:org.mitre.oval:tst:2724"/>
        <criterion comment="the version of wmplayer.exe is less than 8.0.0.4482" negate="false" test_ref="oval:org.mitre.oval:tst:2723"/>
        <criterion comment="Patch wm320920_8.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:28" version="1" class="vulnerability">
      <metadata>
        <title>SKK/DDSKK Insecure Temporary File Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>skk</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0539" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0539"/>
        <description>skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable config">
          <criterion comment="ddskk version is less than 11.6.0-11.90" negate="false" test_ref="oval:org.mitre.oval:tst:3061"/>
          <criterion comment="ddskk-xemacs version is less than 11.6.0-11.90" negate="false" test_ref="oval:org.mitre.oval:tst:3060"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:692" version="2">
      <metadata>
        <title>Microsoft Visio 2002, SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Visio 2002, SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.484-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visio 2002, SP2 is installed" test_ref="oval:org.mitre.oval:tst:481"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:279" version="2">
      <metadata>
        <title>Microsoft Office Property Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-2389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2389" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to record lengths, aka "Microsoft Office Property Vulnerability," a different vulnerability than CVE-2006-1316.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2006-09-29T12:51:00.000-04:00" comment="Fixed reference typo.  Was CVE-2006-3289.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-10-16T15:58:37.077-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:35.097-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Project 2002, SP1" operator="AND">
          <extend_definition comment="Microsoft Project 2002, SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Visio 2002" operator="AND">
          <extend_definition comment="Microsoft Visio 2002 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
        <criteria comment="Project 2000, SP1" operator="AND">
          <extend_definition comment="Microsoft Project 2000, SP1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Catch-all for the 2000 version of the Mso9.dll library." operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8944" test_ref="oval:org.mitre.oval:tst:122"/>
        </criteria>
        <criteria comment="Catchall for the 2002 version of the Mso.dll library." operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6804.0" test_ref="oval:org.mitre.oval:tst:141"/>
        </criteria>
        <criteria comment="Catchall for the 2003 version of the Mso.dll library." operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8028.0" test_ref="oval:org.mitre.oval:tst:169"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2786" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false" test_ref="oval:org.mitre.oval:tst:567"/>
          <criterion comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:278" version="1" class="vulnerability">
      <metadata>
        <title>Linux ioperm Privilege Restriction Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0246" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0246"/>
        <description>The ioperm system call in Linux kernel 2.4.20 and earlier does not properly restrict privileges, which allows local users to gain read or write access to certain I/O ports.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2770" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 9 CDE ToolTalk Database Server Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-01-24T02:39:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1169"/>
          <criterion comment="Patch 112808-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1168"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:277" version="1" class="vulnerability">
      <metadata>
        <title>SMB Session Digital Signature Sidestep</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB Signing (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1256"/>
        <description>The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T11:09:00.000-04:00" comment="modified wft-276 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of srvsvc.dll is less than 5.0.2195.6110" negate="false" test_ref="oval:org.mitre.oval:tst:2730"/>
          <criterion comment="Patch Q329170 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2729"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMB Signing enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2728"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2753" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" negate="false" test_ref="oval:org.mitre.oval:tst:479"/>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2738" version="1" class="vulnerability">
      <metadata>
        <title>Visio Professional URL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visio Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0848"/>
        <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Visio Professional 2002 with service pack 2" negate="false" test_ref="oval:org.mitre.oval:tst:481"/>
        <criterion comment="Patch KB873354 installed" negate="true" test_ref="oval:org.mitre.oval:tst:480"/>
        <criterion comment="the version of mso.dll is less than 10.0.6735.0" negate="false" test_ref="oval:org.mitre.oval:tst:554"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2734" version="1" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (Terminal Server Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of wins.exe is less than 4.0.1381.33618" negate="false" test_ref="oval:org.mitre.oval:tst:482"/>
          <criterion comment="the patch KB870763 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:865"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2731" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Font Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0060"/>
        <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false" test_ref="oval:org.mitre.oval:tst:1025"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2730" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed OVAL2730</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for MDAC 2.5 since this definition is dependent on the MDAC version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="MDAC 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="the version of msadco.dll is less than 2.53.6202.0" negate="false" test_ref="oval:org.mitre.oval:tst:483"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:272" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Domain Restriction Bypass Cross-Frame Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1217"/>
        <description>Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document property, which bypasses &lt;frame> and &lt;iframe> domain restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2719" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Management Error in OpenSSH</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>OpenSSH</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0693"/>
        <description>A "buffer management error" in buffer_append_space of buffer.c for OpenSSH before 3.7 may allow remote attackers to execute arbitrary code by causing an incorrect amount of memory to be freed and corrupting the heap, a different vulnerability than CVE-2003-0695.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Patch 113273-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:485"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="sshd running" negate="false" test_ref="oval:org.mitre.oval:tst:484"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:271" version="1" class="vulnerability">
      <metadata>
        <title>SQL Server OpenDataSource/OpenRowset Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0056"/>
        <description>Buffer overflow in SQL Server 7.0 and 2000 allows remote attackers to execute arbitrary code via a long OLE DB provider name to (1) OpenDataSource or (2) OpenRowset in an ad hoc connection.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-275 - wft-275 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-274 - wft-274 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:20:00.000-04:00" comment="modified wft-274 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:22:00.000-04:00" comment="modified wft-275 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File sqlservr.exe version3 is less than 2000.80.578.0" negate="false" test_ref="oval:org.mitre.oval:tst:2732"/>
        <criterion comment="File xpstar.dll version3 is less than 2000.80.561.0" negate="false" test_ref="oval:org.mitre.oval:tst:2731"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2706" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Office 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-09-27T12:00:00.000-04:00" comment="changed affected product from GDI+ and office2003 to just office 2003">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-13T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-495 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Changed criteria to remove test for KB838905.  Changed criteria to use a new test for gdiplus.dll version, which uses a registry key specific to MS Office to determine the file's path.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:487"/>
        <criterion comment="the version of Gdiplus.dll for Microsoft Office is less than 6.0.3264.0" negate="false" test_ref="oval:org.mitre.oval:tst:486"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2705" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP/Server 2003 DirectPlay Denial of Service (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0202"/>
        <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-06-16T12:00:00.000-04:00" comment="Changed Status to Draft; Added cmp-970">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <modified date="2004-07-06T12:00:00.000-04:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-07-12T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-21T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP or Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:488"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="AND" comment="DirectX 8.1 without kb839643 installed">
          <criterion comment="the version of dplayx.dll is less than 5.2.3790.163 on 64-bit edition" negate="false" test_ref="oval:org.mitre.oval:tst:548"/>
          <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:598"/>
          <criterion comment="the patch kb839643 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:597"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:270" version="2">
      <metadata>
        <title>TCP Connection Reset Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230" source="CVE"/>
        <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:34.412-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:44.080-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.1.2600.1886" test_ref="oval:org.mitre.oval:tst:68"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.1.2600.2975" test_ref="oval:org.mitre.oval:tst:86"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.2771" test_ref="oval:org.mitre.oval:tst:131"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.576" test_ref="oval:org.mitre.oval:tst:171"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Tcpip6.sys is less than 5.2.3790.2771" test_ref="oval:org.mitre.oval:tst:131"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:27" version="2" class="vulnerability">
      <metadata>
        <title>IE v5.01 Content Disposition/Type Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0193"/>
        <description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the "Content Disposition" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:19.605-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3064"/>
          <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.0.3504.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3062"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2692" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:269" version="2">
      <metadata>
        <title>PowerPoint Malformed Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference ref_id="CVE-2006-4694" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4694" source="CVE"/>
        <description>Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office XP and Office 2003 allows user-assisted attackers to execute arbitrary code via a crafted record in a PPT file, as exploited by malware such as Exploit:Win32/Controlppt.W, Exploit:Win32/Controlppt.X, and Exploit-PPT.d/Trojan.PPDropper.F. NOTE: it has been reported that the attack vector involves SlideShowWindows.View.GotoNamedShow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:33.556-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:43.053-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="PowerPoint 2000" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of powerpnt.exe is less than 9.0.0.8952" test_ref="oval:org.mitre.oval:tst:165"/>
        </criteria>
        <criteria comment="PowerPoint 2002" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of powerpnt.exe is less than 10.0.6819.0" test_ref="oval:org.mitre.oval:tst:50"/>
        </criteria>
        <criteria comment="PowerPoint 2003" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8110.0" test_ref="oval:org.mitre.oval:tst:184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2689" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Large Window Size TCP RST Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0230"/>
        <description>TCP, when using a large Window Size, makes it easier for remote attackers to guess sequence numbers and cause a denial of service (connection loss) to persistent TCP connections by repeatedly injecting a TCP RST packet, especially in protocols that use long-lived connections, such as BGP.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:52.482-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.336" negate="false" test_ref="oval:org.mitre.oval:tst:2354"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2685" version="2" class="vulnerability">
      <metadata>
        <title>Word 2000 Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:19.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8929" negate="false" test_ref="oval:org.mitre.oval:tst:591"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:268" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Messenger Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0717"/>
        <description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:21:00.000-04:00" comment="CMP-66 has been added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of wkssvc.dll exists">
            <criteria operator="AND" comment="no service pack is installed and wkssvc.dll is less than 5.1.2600.120">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of wkssvc.dll is less than 5.1.2600.120" negate="false" test_ref="oval:org.mitre.oval:tst:2736"/>
            </criteria>
            <criteria operator="AND" comment="service pack 1 is installed and wkssvc.dll is less than 5.1.2600.1301">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of wkssvc.dll is less than 5.1.2600.1301" negate="false" test_ref="oval:org.mitre.oval:tst:2735"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of msgsvc.dll exists">
            <criteria operator="AND" comment="no service pack is installed and msgsvc.dll is less than 5.1.2600.120">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of msgsvc.dll is less than 5.1.2600.120" negate="false" test_ref="oval:org.mitre.oval:tst:2734"/>
            </criteria>
            <criteria operator="AND" comment="service pack 1 is installed and msgsvc.dll is less than 5.1.2600.1301">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of msgsvc.dll is less than 5.1.2600.1301" negate="false" test_ref="oval:org.mitre.oval:tst:2733"/>
            </criteria>
          </criteria>
          <criterion comment="the patch q828035 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2796"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the messenger service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2673" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2000 File Handler Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0846"/>
        <description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-18T12:07:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:19.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office 2000 Professional Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:489"/>
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2671" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Certificate Validation Identity Spoofing Vulnerability (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0862"/>
        <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-12T12:00:00.000-04:00" comment="negated patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false" test_ref="oval:org.mitre.oval:tst:1229"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2670" version="2" class="vulnerability">
      <metadata>
        <title>Office 2000 WordPerfect Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office 2000 SP3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0573" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0573"/>
        <description>Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-09-29T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-10T12:00:00.000-04:00" comment="modified wft-489 - corrected registry path check for .dll file">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-11T09:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-02T09:01:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 422 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:18.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msconv97.dll is less than 2003.1100.6252.0" negate="false" test_ref="oval:org.mitre.oval:tst:492"/>
        <criterion comment="the patch kb873380 for Office 2000 SP3 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:491"/>
        <criteria operator="OR" comment="Microsoft Office 2000 (Premium or Professional) Service Pack 3 is installed">
          <criterion comment="Microsoft Office 2000 Premium Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:490"/>
          <criterion comment="Microsoft Office 2000 Professional Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:489"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:267" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:44.992-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.447-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3750"/>
        <criterion comment="SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3342"/>
        <criterion comment="64-bit version" negate="true" test_ref="oval:org.mitre.oval:tst:3257"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.1.2600.1711" negate="false" test_ref="oval:org.mitre.oval:tst:3367"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:266" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (SP2) CSRSS Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Client Server Runtime System (CSRSS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
        <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false" test_ref="oval:org.mitre.oval:tst:2738"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2657" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6.0 for Server 2003 Malformed Email Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0215"/>
        <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-26T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-26T10:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="Outlook Express 6 for Windows 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2855"/>
          <criterion comment="the patch kb823353 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:668"/>
          <criteria operator="OR" comment="a vulnerable version of inetcomm.dll exisits">
            <criterion comment="machine has followed the GDR update path and inetcomm.dll is less than 6.0.3790.181" negate="false" test_ref="oval:org.mitre.oval:tst:499"/>
            <criterion comment="machine has followed the QFE update path and inetcomm.dll is less than 6.0.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:498"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="all users have the preview pane disabled" negate="false" test_ref="oval:org.mitre.oval:tst:667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:264" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 RPCSS DCOM Buffer Overflow (Blaster, Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2638" version="1" class="vulnerability">
      <metadata>
        <title>Windows 98 Long Share Names Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0214"/>
        <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 98 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1345"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:263" version="1" class="vulnerability">
      <metadata>
        <title>Gaim DoS via Malformed MSN Message</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Gaim</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1934" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1934"/>
        <description>Gaim before 1.3.1 allows remote attackers to cause a denial of service (crash) via a malformed MSN message that leads to a memory allocation of a large size, possibly due to an integer signedness error.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gaim RPM earlier than 1:1.3.1-0.el3" negate="false" test_ref="oval:org.mitre.oval:tst:2740"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/gaim is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:2739"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2621" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL Denial of Service Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Sun Crypto Accelerator 4000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0079"/>
        <description>The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T09:44:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 114796-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:501"/>
          <criterion comment="Sun Crypto Accelerator 4000 software installed" negate="false" test_ref="oval:org.mitre.oval:tst:500"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:262" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kernel Debugger-based Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of kernel32.dll is less than 5.0.2195.6011" negate="false" test_ref="oval:org.mitre.oval:tst:2741"/>
        <criterion comment="the patch Q811493 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2885"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2611" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 HijackClick 3 / Script in Image Tag File Download Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0841" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0841"/>
        <description>Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:261" version="1" class="vulnerability">
      <metadata>
        <title>Linux Route Cache / Netfilter Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Netfilter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0244"/>
        <description>The route cache implementation in Linux 2.4, and the Netfilter IP conntrack module, allows remote attackers to cause a denial of service (CPU consumption) via packets with forged source addresses that cause a large number of hash table collisions.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:260" version="1" class="vulnerability">
      <metadata>
        <title>Netfilter Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Netfilter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0187"/>
        <description>The connection tracking core of Netfilter for Linux 2.4.20, with CONFIG_IP_NF_CONNTRACK enabled or the ip_conntrack module loaded, allows remote attackers to cause a denial of service (resource consumption) due to an inconsistency with Linux 2.4.20's support of linked lists, which causes Netfilter to fail to identify connections with an UNCONFIRMED status and use large timeouts.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.20-13.9" negate="false" test_ref="oval:org.mitre.oval:tst:2742"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:26" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Network Connection Manager Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Network Connection Manager (NCM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0720" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0720"/>
        <description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        <criterion comment="the version of netman.dll is less than 5.0.2195.5974" negate="false" test_ref="oval:org.mitre.oval:tst:3072"/>
        <criterion comment="Patch Q326886 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2592" version="1" class="vulnerability">
      <metadata>
        <title>KCMS KCS_OPEN_PROFILE File Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0027"/>
        <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" negate="false" test_ref="oval:org.mitre.oval:tst:505"/>
          <criterion comment="Patch 114636-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:504"/>
          <criterion comment="Patch 107337-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:503"/>
          <criterion comment="Patch 111400-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:502"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains kcms_server" negate="false" test_ref="oval:org.mitre.oval:tst:2930"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2590" version="1" class="vulnerability">
      <metadata>
        <title>OpenSSL Double-free Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sun Cluster</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0545" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0545"/>
        <description>Double-free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an SSL client certificate with a certain invalid ASN.1 encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T03:11:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 113505-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:511"/>
          <criterion comment="Patch 113508-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:510"/>
          <criterion comment="Patch 115054-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:509"/>
          <criterion comment="Patch 115055-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:508"/>
          <criterion comment="SunCluster Component SUNWscvw installed" negate="false" test_ref="oval:org.mitre.oval:tst:507"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running with SunPlex Manager config" negate="false" test_ref="oval:org.mitre.oval:tst:506"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:259" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Unknown Vector SMB Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1206"/>
        <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="a vulnerable version of srv.sys exists">
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of srv.sys exists">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="the version of srv.sys is less than 5.2.3790.324" negate="false" test_ref="oval:org.mitre.oval:tst:2746"/>
          </criteria>
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of srv.sys exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="the version of srv.sys is less than 5.2.3790.2437" negate="false" test_ref="oval:org.mitre.oval:tst:2745"/>
          </criteria>
          <criteria operator="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of srv.sys exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of srv.sys is less than 5.2.3790.2437" negate="false" test_ref="oval:org.mitre.oval:tst:2745"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB896422 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2743"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2580" version="1" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows Server 2003 or Windows Server 2003 64-bit Edition is installed">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.2.3790.245" negate="false" test_ref="oval:org.mitre.oval:tst:512"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:258" version="2" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T06:22:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:57.024-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3541.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2751"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2572" version="1" class="vulnerability">
      <metadata>
        <title>DoS Vulnerability in libpng function png_handle_iCCP()</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0598" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0598"/>
        <description>The png_handle_iCCP function in libpng 1.2.5 and earlier allows remote attackers to cause a denial of service (application crash) via a certain PNG image that triggers a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Netscape installed" negate="false" test_ref="oval:org.mitre.oval:tst:901"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2570" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Hyperlink Object Library Unchecked Buffer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Hyperlink Object Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0057"/>
        <description>The Hyperlink Object Library for Windows 98, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a crafted link that triggers an "unchecked buffer" in the library, possibly due to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-03-02T09:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the version of hlink.dll is less than 5.2.3790.227" negate="false" test_ref="oval:org.mitre.oval:tst:2399"/>
        <criterion comment="the patch kb888113 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2398"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2568" version="2" class="vulnerability">
      <metadata>
        <title>License Logging Service Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0050"/>
        <description>The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibly execute arbtirary code, aka the "License Logging Service Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:52.285-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb885834 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2477"/>
          <criterion comment="the version of Llssrv.exe is less than 5.0.2195.7021" negate="false" test_ref="oval:org.mitre.oval:tst:513"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="license logging service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2475"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2562" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Font Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0060"/>
        <description>Buffer overflow in the font processing component of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:2358"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:256" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Print Spooler Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1984"/>
        <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:44.827-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.267-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3750"/>
        <criterion comment="SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3341"/>
        <criterion comment="the version of spoolsv.exe is less than 5.1.2600.2696" negate="false" test_ref="oval:org.mitre.oval:tst:3950"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2559" version="1" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE6 for Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:44:00.000-04:00" comment="modified wft-594 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.279" negate="false" test_ref="oval:org.mitre.oval:tst:515"/>
          <criterion comment="the patch kb890923 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:514"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:255" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://sunsolve9.sun.com/search/document.do?assetkey=1-26-101519-1&amp;searchclause="/>
        <description>Solaris 9 patches 112908-12 and 115168-03 introduced a logging flaw that can log passwords in clear text.  This can lead to privilege escalation for a local user.  It can also lead to the compromise of other systems if passwords are reuse introduced a logging flaw that can log passwords in clear text.  This can lead to privilege escalation for a local user.  It can also lead to the compromise of other systems if passwords are reused.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:44.676-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:52.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101519 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
            <criterion comment="Patch 112908-12 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4105"/>
            <criterion comment="Patch 112908-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3957"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101519 criteria." negate="false">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
            <criterion comment="Patch 115168-03 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3258"/>
            <criterion comment="Patch 115168-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4013"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured as a kerberos client" negate="false" test_ref="oval:org.mitre.oval:tst:3487"/>
          <criterion comment="pam_krb5 is an auth module with debug enabled" negate="false" test_ref="oval:org.mitre.oval:tst:4074"/>
          <criterion comment="Logging of LOG_DEBUG level messages is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3394"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2545" version="1" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (Windows XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-176 - access DLL via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-29T12:00:00.000-04:00" comment="modified wrt-45 - deleted an extra space after Filelist">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-04-22T12:00:00.000-04:00" comment="modified wrt-45 - Removed extra space between 'Windows XP' in the key field">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2005-04-27T12:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criterion comment="the version of hypertrm.dll is less than 5.1.2600.2563" negate="false" test_ref="oval:org.mitre.oval:tst:516"/>
          <criterion comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed" negate="true" test_ref="oval:org.mitre.oval:tst:828"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2541" version="2" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:52.038-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 Server is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
          </criteria>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of wins.exe is less than 5.0.2195.7005" negate="false" test_ref="oval:org.mitre.oval:tst:517"/>
          <criterion comment="the patch KB870763 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:865"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:254" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel ptrace Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0127"/>
        <description>The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root privileges by using ptrace to attach to a child process that is spawned by the kernel.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-25T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kernel version = 2.4.20-6" negate="false" test_ref="oval:org.mitre.oval:tst:2753"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="kernel 2.4.20-6 or earlier is running" negate="false" test_ref="oval:org.mitre.oval:tst:2752"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2539" version="1" class="vulnerability">
      <metadata>
        <title>BIND SIG Resource Records Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1219"/>
        <description>Buffer overflow in named in BIND 4 versions 4.9.10 and earlier, and 8 versions 8.3.3 and earlier, allows remote attackers to execute arbitrary code via a certain DNS server response containing SIG resource records (RR).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 106938-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:623"/>
          <criterion comment="Patch 109326-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:622"/>
          <criterion comment="Patch 112970-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2537" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T05:29:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3534.2800" negate="false" test_ref="oval:org.mitre.oval:tst:519"/>
          <criterion comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:518"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2536" version="2" class="vulnerability">
      <metadata>
        <title>Kerberos 5 KDC Heap Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0082"/>
        <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:18.623-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>Vulnerability exists in standard Solaris kerberos and SEAM.  This definition only covers Solaris kerberos</note>
      </notes>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criteria operator="OR" comment="Kerberos v5 (any SUNWkrbr/SUNWkrbu/SUNWkrbux) installed">
            <criterion comment="Kerberos v5 - Root (SUNWkrbr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:527"/>
            <criterion comment="Kerberos v5 - Usr (SUNWkrbu/SUNWkrbux) installed" negate="false" test_ref="oval:org.mitre.oval:tst:526"/>
          </criteria>
          <criteria operator="AND" comment="Patches 112237-09 and 112390-08 or later installed" negate="true">
            <criterion comment="Patch 112237-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:525"/>
            <criterion comment="Patch 112390-08 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:524"/>
          </criteria>
          <criteria operator="AND" comment="Patches 112925-03,112923-03,112921-02, and 112908-10 or later installed" negate="true">
            <criterion comment="Patch 112925-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:523"/>
            <criterion comment="Patch 112923-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:522"/>
            <criterion comment="Patch 112921-02 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:521"/>
            <criterion comment="Patch 112908-10 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:520"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:253" version="1" class="vulnerability">
      <metadata>
        <title>SQL Server Format String Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0879" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0879"/>
        <description>Format string vulnerability in the C runtime functions in SQL Server 7.0 and 2000 allows attackers to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Patch Q305601 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2754"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2516" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (32-Bit) DirectPlay Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0202"/>
        <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-06-16T12:00:00.000-04:00" comment="Changed Status to Draft; Added cmp-969">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <modified date="2004-07-06T12:00:00.000-04:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-07-12T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-21T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criteria operator="OR" comment="DirectX without KB839643 Installed on Windows Server 2003">
          <criteria operator="AND" comment="DirectX 8.2 without DirectX82-KB839643-x86-ENU.EXE Installed">
            <criterion comment="the version of dplayx.dll is less than 5.2.3677.144" negate="false" test_ref="oval:org.mitre.oval:tst:605"/>
            <criterion comment="DirectX 8.2 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:604"/>
            <criterion comment="Patch DirectX82-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:603"/>
          </criteria>
          <criteria operator="AND" comment="DirectX 9.0 without DirectX9-KB839643-x86-ENU.EXE Installed">
            <criterion comment="the version of dplayx.dll is less than 5.3.0.903" negate="false" test_ref="oval:org.mitre.oval:tst:602"/>
            <criterion comment="DirectX 9.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:601"/>
            <criterion comment="Patch DirectX90-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:600"/>
          </criteria>
          <criteria operator="AND" comment="DirectX 8.1 without WindowsServer2003-KB839643-x86-ENU.EXE Installed">
            <criterion comment="the version of dplayx.dll is less than 5.2.3790.163" negate="false" test_ref="oval:org.mitre.oval:tst:528"/>
            <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:598"/>
            <criterion comment="the patch kb839643 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:597"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2505" version="1" class="vulnerability">
      <metadata>
        <title>RPC Runtime Library Denial of Service and Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0569" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0569"/>
        <description>The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-18T11:46:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of rpcrt4.dll is less than 4.0.1381.7299" negate="false" test_ref="oval:org.mitre.oval:tst:530"/>
        <criterion comment="Patch KB873350 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:529"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:250" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos krb4 Ticket Splicing Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0139" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0139"/>
        <description>Certain weaknesses in the implementation of version 4 of the Kerberos protocol (krb4) in the krb5 distribution, when triple-DES keys are used to key krb4 services, allow an attacker to create krb4 tickets for unauthorized principals using a cut-and-paste attack and "ticket splicing."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-libs version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2756"/>
        <criteria operator="OR" comment="krb5-server or krb5-workstation installed">
          <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
          <criterion comment="krb5-workstation version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:25" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Chunked Encoding Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0079"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2495" version="1" class="vulnerability">
      <metadata>
        <title>Windows Utility Manager Shatter Message Vulnerability II</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Utility Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0213"/>
        <description>Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which allows local users to gain system privileges via a "Shatter" style attack that sends a Windows message to cause Utility Manager to launch winhlp32 by directly accessing the context sensitive help and bypassing the GUI, then sending another message to winhlp32 in order to open a user-selected file, a different vulnerability than CVE-2003-0908.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of Sp3res.dll is less than 5.0.2195.6928" negate="false" test_ref="oval:org.mitre.oval:tst:533"/>
        <criterion comment="the version of Umandlg.dll is less than 1.0.0.5" negate="false" test_ref="oval:org.mitre.oval:tst:532"/>
        <criterion comment="the patch kb842526 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:531"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2487" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Plug-in Navigation Address Bar Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0843" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0843"/>
        <description>Internet Explorer 5.5 and 6 does not properly handle plug-in navigation, which allows remote attackers to alter displayed address bars and thereby spoof web pages, facilitating phishing attacks, aka the "Plug-in Navigation Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:248" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos krb4 Plaintext Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0138" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0138"/>
        <description>Version 4 of the Kerberos protocol (krb4), as used in Heimdal and other packages, allows an attacker to impersonate any principal in a realm via a chosen-plaintext attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-libs version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2756"/>
        <criteria operator="OR" comment="krb5-server or krb5-workstation installed">
          <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
          <criterion comment="krb5-workstation version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2755"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:246" version="1" class="vulnerability">
      <metadata>
        <title>Network News Transfer Protocol Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Network News Transport Protocol (NNTP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0574" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0574"/>
        <description>The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly related to improper length validation and an "unchecked buffer," leading to off-by-one and heap-based buffer overflows.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T09:17:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Exchange Server 2003 is installed on Windows Server 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="Exchange Server 2003 (gold edition) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2760"/>
          </criteria>
          <criterion comment="the version of nntpsvc.dll is less than 6.0.3790.206" negate="false" test_ref="oval:org.mitre.oval:tst:2759"/>
          <criterion comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2758"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the NNTP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2757"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2448" version="1" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing on Double Byte Character Set Systems Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0844" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0844"/>
        <description>Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Character Set Systems Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.219" negate="false" test_ref="oval:org.mitre.oval:tst:535"/>
          <criterion comment="the patch kb834707 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:534"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2447" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Indexing Service Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Indexing Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0897"/>
        <description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criterion comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" negate="false" test_ref="oval:org.mitre.oval:tst:537"/>
        <criterion comment="the patch Windows XP KB871250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:536"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:244" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos KDC Heap Corruption Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0082" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0082"/>
        <description>The Key Distribution Center (KDC) in Kerberos 5 (krb5) 1.2.7 and earlier allows remote, authenticated attackers to cause a denial of service (crash) on KDCs within the same realm using a certain protocol request that causes the KDC to corrupt its heap (aka "buffer underrun").</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:243" version="2">
      <metadata>
        <title>Microsoft Excel Malformed FNGROUPCOUNT value Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1308" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:18.439-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:36.766-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2428" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP/Server 2003 (64-Bit) Enhanced Metafile Image Format Rendering Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Enhanced Metafile (EMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0209"/>
        <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:29:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-10-13T11:43:00.000-04:00" comment="changed OS">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of win32k.sys is less than 5.2.3790.198" negate="false" test_ref="oval:org.mitre.oval:tst:738"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criteria operator="OR" comment="Windows 2003 Server or Windows XP 64-bit">
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2423" version="1" class="vulnerability">
      <metadata>
        <title>ypxfrd File Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>NIS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1199"/>
        <description>The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="NIS Server - User (SUNWypu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:547"/>
          <criterion comment="Patch 106541-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:546"/>
          <criterion comment="Patch 109328-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:545"/>
          <criterion comment="Patch 113579-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:544"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypxfrd running" negate="false" test_ref="oval:org.mitre.oval:tst:543"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2418" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla, Firefox, Thunderbird User Interface Hijacking Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0764"/>
        <description>Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2415" version="2" class="vulnerability">
      <metadata>
        <title>Word 2002 Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:18.191-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.6754.0" negate="false" test_ref="oval:org.mitre.oval:tst:621"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2413" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) DirectPlay Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0202"/>
        <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-06-16T12:00:00.000-04:00" comment="Changed Status to Draft; Added cmp-967">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <modified date="2004-07-06T12:00:00.000-04:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-07-12T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-21T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-09-14T10:07:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-09-14T10:07:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="DirectX 8.1 without kb839643 installed">
          <criterion comment="the version of dplayx.dll is less than 5.2.3790.163 on 64-bit edition" negate="false" test_ref="oval:org.mitre.oval:tst:548"/>
          <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:598"/>
          <criterion comment="the patch kb839643 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:597"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 64-bit with SP1 (or earlier) installed">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:241" version="1" class="vulnerability">
      <metadata>
        <title>Scob and Toofer Internet Explorer v5.5,SP2 Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549"/>
        <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
          <criterion comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false" test_ref="oval:org.mitre.oval:tst:2762"/>
          <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:24" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS FTP Connection Status Request Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>FTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0073" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0073"/>
        <description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3074"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2394" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T04:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:51.828-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of nddenb32.dll is less than 4.0.1381.7268" negate="false" test_ref="oval:org.mitre.oval:tst:550"/>
        <criterion comment="the version of netdde.exe is less than 4.0.1381.7280" negate="false" test_ref="oval:org.mitre.oval:tst:549"/>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:239" version="2">
      <metadata>
        <title>Microsoft Publisher 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Publisher 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-21T07:56:35">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:44.565-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:51.748-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Publisher 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:24"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2385" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Channel Definition Format Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0056"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate certain URLs in Channel Definition Format (CDF) files, which allows remote attackers to obtain sensitive information or execute arbitrary code, aka the "Channel Definition Format (CDF) Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2381" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of helpctr.exe is less than 5.1.2600.1515" negate="true" test_ref="oval:org.mitre.oval:tst:1321"/>
        <criterion comment="the version of shell32.dll is less than 6.0.3790.168" negate="false" test_ref="oval:org.mitre.oval:tst:551"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2379" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000 Media Player PNG Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1244"/>
        <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-23T08:48:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified objects 733, 734, 735, 736, 738, and 739 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:17.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Media Player 9.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:1004"/>
          <criterion comment="the version of wmp.dll is les than 9.0.0.3250" negate="false" test_ref="oval:org.mitre.oval:tst:1003"/>
          <criterion comment="The patch KB885492 is installed on Windows 2000" negate="true" test_ref="oval:org.mitre.oval:tst:552"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST">
            <criterion comment=".asx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:1001"/>
            <criterion comment=".wax EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:1000"/>
            <criterion comment=".wvx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:999"/>
            <criterion comment=".wpl EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:998"/>
            <criterion comment=".wmx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:997"/>
            <criterion comment=".wms EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:996"/>
            <criterion comment=".wmz EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:995"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2378" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in libpng</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Netscape installed" negate="false" test_ref="oval:org.mitre.oval:tst:901"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:237" version="1" class="vulnerability">
      <metadata>
        <title>Troubleshooter ActiveX Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0662"/>
        <description>Buffer overflow in Troubleshooter ActiveX Control (Tshoot.ocx) in Microsoft Windows 2000 SP4 and earlier allows remote attackers to execute arbitrary code via an HTML document with a long argument to the RunQuery2 method.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of tshoot.ocx is less than 1.0.1.2125" negate="false" test_ref="oval:org.mitre.oval:tst:2764"/>
          <criterion comment="the patch kb826232 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2763"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:236" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T11:01:00.000-04:00" comment="modified wft-267 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1458" negate="false" test_ref="oval:org.mitre.oval:tst:2765"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2351" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 COM Structured Storage Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0047"/>
        <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T10:39:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.1.2600.2595" negate="false" test_ref="oval:org.mitre.oval:tst:1099"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:235" version="1" class="vulnerability">
      <metadata>
        <title>SQL Server Named Pipe Hijacking</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0230"/>
        <description>Microsoft SQL Server 7, 2000, and MSDE allows local users go gain privileges by hijacking a named pipe during the authentication of another user, aka the "Named Pipe Hijacking" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-62 - Added &quot;80&quot; to the registry component. So that new component value is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\80\SharedCode. This key specifes the location of the  file that should be tested.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T10:31:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-70 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-73 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-78 - wft-78 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-79 - wft-79 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:35:00.000-04:00" comment="modified wft-51 - wft-51 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:36:00.000-04:00" comment="modified wft-52 - wft-52 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:37:00.000-04:00" comment="modified wft-53 - wft-53 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:38:00.000-04:00" comment="modified wft-54 - wft-54 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:39:00.000-04:00" comment="modified wft-60 - wft-60 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:45:00.000-04:00" comment="modified wft-61 - wft-61 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:56:00.000-04:00" comment="modified wft-63 - wft-63 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T11:52:00.000-04:00" comment="modified wft-64 - wft-64 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-72 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:46:00.000-04:00" comment="modified wft-61 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:21:00.000-04:00" comment="modified wft-63 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:23:00.000-04:00" comment="modified wft-64 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-73 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:27:00.000-04:00" comment="modified wft-72 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:28:00.000-04:00" comment="modified wft-70 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:29:00.000-04:00" comment="modified wft-71 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File console.exe version3 is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2780"/>
        <criterion comment="File dbmslpcn.dll version3 is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2779"/>
        <criterion comment="File sqlmap70.dll version3 is less than 2000.80.811.0" negate="false" test_ref="oval:org.mitre.oval:tst:2778"/>
        <criterion comment="File sqlrepss.dll version3 is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2777"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2776"/>
        <criterion comment="the version of ssmslpcn.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2775"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2774"/>
        <criterion comment="the version of ssnmpn70.dll is less than 2000.80.818.0" negate="false" test_ref="oval:org.mitre.oval:tst:2773"/>
        <criterion comment="the version of ums.dll is less than 2000.80.816.0" negate="false" test_ref="oval:org.mitre.oval:tst:2772"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.800.0" negate="false" test_ref="oval:org.mitre.oval:tst:2771"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.778.0" negate="false" test_ref="oval:org.mitre.oval:tst:2770"/>
        <criterion comment="File msgprox.dll version3 is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2769"/>
        <criterion comment="the version of replprov.dll is less than 2000.80.798.0" negate="false" test_ref="oval:org.mitre.oval:tst:2768"/>
        <criterion comment="File replrec.dll version3 is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2767"/>
        <criterion comment="File sqlvdi.dll version3 is less than 2000.80.765.0" negate="false" test_ref="oval:org.mitre.oval:tst:2766"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2348" version="2" class="vulnerability">
      <metadata>
        <title>Windows Project Professional URL Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Project Professional 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0848" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0848"/>
        <description>Buffer overflow in Microsoft Office XP allows remote attackers to execute arbitrary code via a link with a URL file location containing long inputs after (1) "%00 (null byte) in .doc filenames or (2) "%0a" (carriage return) in .rtf filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-11T12:00:00.000-04:00" comment="removed extra closing curly brace from obj:466">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-09-08T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:17.655-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Project Professional 2002 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:555"/>
        <criterion comment="the version of mso.dll is less than 10.0.6735.0" negate="false" test_ref="oval:org.mitre.oval:tst:554"/>
        <criterion comment="Patch KB873355 installed" negate="true" test_ref="oval:org.mitre.oval:tst:553"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2343" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP RPCSS DCOM Buffer Overflow (Blaster, Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0352"/>
        <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>This bulletin has been superceded by MS03-039.  Definition reflects updated information.</note>
      </notes>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows XP 32-bit OR Windows XP 64-bit is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="A vulnerable version of rpcrt4.dll exists depending on service pack level">
            <criteria operator="AND" comment="no service pack is installed and rpcrt4.dll is less than 5.1.2600.109">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.109" negate="false" test_ref="oval:org.mitre.oval:tst:556"/>
            </criteria>
            <criteria operator="AND" comment="SP1 is installed and the version of rpcrt4.dll is less than 5.1.2600.1254">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1254" negate="false" test_ref="oval:org.mitre.oval:tst:708"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="false" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:764" version="2">
      <metadata>
        <title>Microsoft Excel 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Excel 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:38.198-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Excel 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:888"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:758" version="2">
      <metadata>
        <title>Microsoft Excel 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Excel 2000 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-25T12:05:33">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-09-27T12:29:37.567-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:49.238-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:473" version="2">
      <metadata>
        <title>Microsoft Excel 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Excel 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-25T12:05:33">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1377 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-09-27T12:29:27.866-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.687-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2420"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:439" version="2">
      <metadata>
        <title>Microsoft Excel Viewer is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Excel Viewer is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:47.730-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:55.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Excel Viewer is installed" negate="false" test_ref="oval:org.mitre.oval:tst:61"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:234" version="2">
      <metadata>
        <title>Microsoft Excel Malformed File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel</product>
        </affected>
        <reference ref_id="CVE-2006-2388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2388" source="CVE"/>
        <description>Microsoft Office Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via malformed cell comments, which lead to modification of "critical data offsets" during the rebuilding process.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:17.493-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:36.473-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Excel 2000" operator="AND">
          <extend_definition comment="Microsoft Excel 2000 is installed" definition_ref="oval:org.mitre.oval:def:758"/>
          <criterion comment="the version of excel.exe is less than 9.0.0.8946" test_ref="oval:org.mitre.oval:tst:6"/>
        </criteria>
        <criteria comment="Excel 2002" operator="AND">
          <extend_definition comment="Microsoft Excel 2002 is installed" definition_ref="oval:org.mitre.oval:def:473"/>
          <criterion comment="the version of excel.exe is less than 10.0.6809.0" test_ref="oval:org.mitre.oval:tst:53"/>
        </criteria>
        <criteria comment="Excel 2003" operator="AND">
          <extend_definition comment="Microsoft Excel 2003 is installed" definition_ref="oval:org.mitre.oval:def:764"/>
          <criterion comment="the version of excel.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:18"/>
        </criteria>
        <criteria comment="Excel Viewer" operator="AND">
          <extend_definition comment="Microsoft Excel Viewer is installed" definition_ref="oval:org.mitre.oval:def:439"/>
          <criterion comment="the version of xlview.exe is less than 11.0.8033.0" test_ref="oval:org.mitre.oval:tst:128"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:233" version="2">
      <metadata>
        <title>Microsoft Office 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Office 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:44.461-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:51.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office 2003 is installed" test_ref="oval:org.mitre.oval:tst:487"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:232" version="2">
      <metadata>
        <title>Buffer Overrun in DHCP Client Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DHCP Client</product>
        </affected>
        <reference ref_id="CVE-2006-2372" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2372" source="CVE"/>
        <description>Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:17.179-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:36.164-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.0.2195.7085" test_ref="oval:org.mitre.oval:tst:186"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 (32-bit) is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.1.2600.1847" test_ref="oval:org.mitre.oval:tst:105"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.1.2600.2912" test_ref="oval:org.mitre.oval:tst:5"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.2.3790.2706" test_ref="oval:org.mitre.oval:tst:103"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.2.3790.536" test_ref="oval:org.mitre.oval:tst:82"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of dhcpcsvc.dll is less than 5.2.3790.2706" test_ref="oval:org.mitre.oval:tst:103"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:231" version="1" class="vulnerability">
      <metadata>
        <title>SQL Server Extended Stored Procedure Parameter Parsing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft SQL Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1081" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1081"/>
        <description>The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-04-08T05:25:00.000-04:00" comment="modified wft-85 - wft-85 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T05:28:00.000-04:00" comment="modified wft-86 - wft-86 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T05:35:00.000-04:00" comment="modified wft-87 - wft-87 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T05:55:00.000-04:00" comment="modified wft-88 - wft-88 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-12T12:00:00.000-04:00" comment="modified wft-89 - wft-89 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:48:00.000-04:00" comment="modified wft-85 - Changed comment to match match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:25:00.000-04:00" comment="modified wft-86 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:26:00.000-04:00" comment="modified wft-87 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:27:00.000-04:00" comment="modified wft-88 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-27T01:28:00.000-04:00" comment="modified wft-89 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="File odsole70.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2784"/>
        <criterion comment="File xpqueue.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2783"/>
        <criterion comment="File xprepl.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2782"/>
        <criterion comment="File xpstar.dll Version3 is less than 2000.80.223.0" negate="false" test_ref="oval:org.mitre.oval:tst:2781"/>
        <criterion comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" negate="true" test_ref="oval:org.mitre.oval:tst:2966"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2300" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server 2003 (INTERIM) Routing Engine Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>SMTP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0840" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0840"/>
        <description>The SMTP (Simple Mail Transfer Protocol) component of Microsoft Windows XP 64-bit Edition, Windows Server 2003, Windows Server 2003 64-bit Edition, and the Exchange Routing Engine component of Exchange Server 2003, allows remote attackers to execute arbitrary code via a malicious DNS response message containing length values that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T10:33:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <modified date="2004-10-26T09:17:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="The version of smtpsvc.dll is less than 6.0.3790.211" negate="false" test_ref="oval:org.mitre.oval:tst:558"/>
          <criterion comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" negate="false" test_ref="oval:org.mitre.oval:tst:557"/>
          <criteria operator="AND" comment="Exchange Server 2003 is installed on Windows Server 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="Exchange Server 2003 (gold edition) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2760"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SMTP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:3054"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:230" version="1" class="vulnerability">
      <metadata>
        <title>xdrmem_bytes() Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0028"/>
        <description>Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="krb5-server version is less than 1.2.7-14" negate="false" test_ref="oval:org.mitre.oval:tst:2785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:23" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Forced Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0026"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4725.2100" negate="false" test_ref="oval:org.mitre.oval:tst:3075"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2292" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Named Pipe Vulnerability (32-bit architecture)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0051" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0051"/>
        <description>The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-02T12:00:00.000-04:00" comment="Added negate to the patch check. Accidentally left off.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-05-04T12:14:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of srvsvc.dll is less than 5.1.2600.2577" negate="false" test_ref="oval:org.mitre.oval:tst:560"/>
        <criterion comment="the patch kb888302 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:559"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2280" version="2" class="vulnerability">
      <metadata>
        <title>DHCP Server Logging Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>DHCP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0899" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0899"/>
        <description>The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Corrected the patch number being checked">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-02-07T12:00:00.000-04:00" comment="negated the patch check">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-02-23T09:25:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:51.630-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" negate="false" test_ref="oval:org.mitre.oval:tst:562"/>
        <criterion comment="the patch KB885249 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:561"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2274" version="2" class="vulnerability">
      <metadata>
        <title>Windows Messenger 5 libpng Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC 2.8</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0597" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0597"/>
        <description>Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-03-13T02:32:00.000-04:00" comment="modified wft-410 - Literal component included \&quot;Program Files\&quot;, but the key in the registry component holds the full path to the Program Files directory (e.g. C:\\Program Files on standard installation).  Modified the literal component so full path when expanded would be correct.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-04-12T05:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-11T12:00:00.000-04:00" comment="added missing windows component to registry key string for obj:473">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-09-08T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:16.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Messenger 5.1 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:564"/>
        <criterion comment="the version of msmsgs.exe is less than 5.1.0.639" negate="false" test_ref="oval:org.mitre.oval:tst:563"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:227" version="2">
      <metadata>
        <title>Microsoft IIS 6.0 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft IIS 6.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:16.652-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.614-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="IIS Major Version equals 6" negate="false" test_ref="oval:org.mitre.oval:tst:170"/>
        <criterion comment="IIS Minor Version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2265" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Terminal Server Kernel Debugger-based Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" negate="false" test_ref="oval:org.mitre.oval:tst:565"/>
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2253" version="1" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE5.01,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3826.2400" negate="false" test_ref="oval:org.mitre.oval:tst:567"/>
          <criterion comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:566"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:225" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Frames Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1187"/>
        <description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame> or &lt;iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4922.900" negate="false" test_ref="oval:org.mitre.oval:tst:2786"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2248" version="1" class="vulnerability">
      <metadata>
        <title>Sun RPC No Timeout Denial of Service on TCP Ports</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libc</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1265"/>
        <description>The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criteria operator="AND" comment="All RPC w/TCP patches installed - CVE-2002-1265">
            <criterion comment="Patch 108748-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:581"/>
            <criterion comment="Patch 108750-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:580"/>
            <criteria operator="OR" comment="Patches 108752-01 or 106541-14 installed">
              <criterion comment="Patch 108752-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:579"/>
              <criterion comment="Patch 106541-14 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:578"/>
            </criteria>
            <criterion comment="Patch 106942-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:577"/>
            <criterion comment="Patch 107477-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:576"/>
            <criterion comment="Patch 108551-03 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:575"/>
            <criterion comment="Patch 108754-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:574"/>
            <criterion comment="Patch 108756-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:573"/>
            <criterion comment="Patch 108758-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:572"/>
            <criterion comment="Patch 108760-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:571"/>
            <criterion comment="Patch 108762-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:570"/>
            <criterion comment="Patch 108764-01 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:569"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpcbind running" negate="false" test_ref="oval:org.mitre.oval:tst:568"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2245" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (32-bit,SP2/64-bit,SP1) Shell CLSID File Type Spoof Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0420" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0420"/>
        <description>The Windows Shell application in Windows 98, Windows ME, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by spoofing the type of a file via a CLSID specifier in the filename, as demonstrated using Internet Explorer 6.0.2800.1106 on Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to drop explicit test for patch kb839645.  Inclusion resulted in false positives w/o incremental patching.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of shell32.dll is less than 6.0.2800.1556" negate="false" test_ref="oval:org.mitre.oval:tst:582"/>
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2222" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail Address Processor Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1337" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1337"/>
        <description>Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Sendmail - user (SUNWsndmu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:587"/>
          <criterion comment="Patch 107684-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:586"/>
          <criterion comment="Patch 110615-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:585"/>
          <criterion comment="Patch 113575-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:584"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Sendmail running" negate="false" test_ref="oval:org.mitre.oval:tst:583"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:222" version="2">
      <metadata>
        <title>Office Malformed Chart Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-3650" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3650" source="CVE"/>
        <description>Microsoft Office 2000, XP, 2003, 2004 for Mac, and v.X for Mac do not properly parse the length of a chart record, which allows remote user-assisted attackers to execute arbitrary code via a Word document with an embedded malformed chart record that triggers an overwrite of pointer values with values from the document, a different vulnerability than CVE-2006-3434, CVE-2006-3864, and CVE-2006-3868.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:32.814-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:42.147-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8950" test_ref="oval:org.mitre.oval:tst:33"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6817.0" test_ref="oval:org.mitre.oval:tst:158"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8107.0" test_ref="oval:org.mitre.oval:tst:98"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2219" version="2" class="vulnerability">
      <metadata>
        <title>IE v6.0 SSL Cached Content Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0845" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0845"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits the target web site.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-26T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-23T12:49:00.000-04:00" comment="modified obj:490 - Chagned the pattern match operation to equals since there was no need for a regular expression.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-06-23T11:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:16.422-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2745.2800" negate="false" test_ref="oval:org.mitre.oval:tst:590"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:589"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" negate="false" test_ref="oval:org.mitre.oval:tst:588"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2216" version="2" class="vulnerability">
      <metadata>
        <title>Word 2000 Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:16.159-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8929" negate="false" test_ref="oval:org.mitre.oval:tst:591"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:493" version="2">
      <metadata>
        <title>Microsoft XML Core Services 5 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft XML Core Services 5 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:45.581-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:55.727-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:49"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:454" version="2">
      <metadata>
        <title>Microsoft XML Core Services 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft XML Core Services 6 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:42.283-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:51.747-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:182"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:415" version="2">
      <metadata>
        <title>Microsoft XML Core Services 3 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft XML Core Services 3 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.00-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:39.106-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:48.903-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:179"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:221" version="2">
      <metadata>
        <title>Microsoft XML Core Services Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft XML Core Services</product>
        </affected>
        <reference ref_id="CVE-2006-4685" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4685" source="CVE"/>
        <description>The XMLHTTP ActiveX control in Microsoft XML Parser 2.6 and XML Core Services 3.0 through 6.0 does not properly handle HTTP server-side redirects, which allows remote user-assisted attackers to access content from other domains.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:32.199-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:41.254-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 3 is installed" definition_ref="oval:org.mitre.oval:def:415"/>
          <criterion comment="The version of Msxml3.dll is less than 8.70.1113.0" negate="false" test_ref="oval:org.mitre.oval:tst:34"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 4 is installed" definition_ref="oval:org.mitre.oval:def:1002"/>
          <criterion comment="The version of Msxml4.dll is less than 4.20.9839.0" negate="false" test_ref="oval:org.mitre.oval:tst:72"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 5 is installed" definition_ref="oval:org.mitre.oval:def:493"/>
          <criterion comment="The version of Msxml5.dll is less than 5.10.2930.0" negate="false" test_ref="oval:org.mitre.oval:tst:87"/>
        </criteria>
        <criteria operator="AND">
          <extend_definition comment="Microsoft XML Core Services 6 is installed" definition_ref="oval:org.mitre.oval:def:454"/>
          <criterion comment="The version of Msxml6.dll is less than 6.0.3888.0" negate="false" test_ref="oval:org.mitre.oval:tst:32"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:696" version="2">
      <metadata>
        <title>Microsoft PowerPoint 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft PowerPoint 2000 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:35.533-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:47.039-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="PowerPoint 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:861"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:666" version="2">
      <metadata>
        <title>Microsoft PowerPoint 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft PowerPoint 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:33.948-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:46.477-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="PowerPoint 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1204"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:305" version="2">
      <metadata>
        <title>Microsoft PowerPoint 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft PowerPoint 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:20.418-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:37.787-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="PowerPoint 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:704"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:220" version="2">
      <metadata>
        <title>PowerPoint Malformed Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference ref_id="CVE-2006-3877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3877" source="CVE"/>
        <description>Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:31.530-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:40.201-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="PowerPoint 2000" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2000 is installed" definition_ref="oval:org.mitre.oval:def:696"/>
          <criterion comment="the version of powerpnt.exe is less than 9.0.0.8952" test_ref="oval:org.mitre.oval:tst:165"/>
        </criteria>
        <criteria comment="PowerPoint 2002" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2002 is installed" definition_ref="oval:org.mitre.oval:def:305"/>
          <criterion comment="the version of powerpnt.exe is less than 10.0.6819.0" test_ref="oval:org.mitre.oval:tst:50"/>
        </criteria>
        <criteria comment="PowerPoint 2003" operator="AND">
          <extend_definition comment="Microsoft PowerPoint 2003 is installed" definition_ref="oval:org.mitre.oval:def:666"/>
          <criterion comment="the version of powerpnt.exe is less than 11.0.8110.0" test_ref="oval:org.mitre.oval:tst:184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:22" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Variant of Chunked Encoding Buffer Overrun</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0147"/>
        <description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2190" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP (32-Bit) DirectPlay Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0202"/>
        <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-06-16T12:00:00.000-04:00" comment="Added cmp-966 to test for vulnerable versions of DirectX">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <modified date="2004-06-17T12:00:00.000-04:00" comment="Re-added cmp-966">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <modified date="2004-07-06T12:00:00.000-04:00" comment="Added the negate attribute with a value of 'true' to the subtest elements referencing patch installations.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-07-12T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-21T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-07T18:56:00.000-04:00" comment="set negate attribute to true in criteria for oval:org.mitre.oval:tst:2845">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-08T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:15.868-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criteria operator="OR" comment="DirectX without KB839643 Installed">
          <criteria operator="AND" comment="DirectX 8.2 without DirectX82-KB839643-x86-ENU.EXE Installed">
            <criterion comment="the version of dplayx.dll is less than 5.2.3677.144" negate="false" test_ref="oval:org.mitre.oval:tst:605"/>
            <criterion comment="DirectX 8.2 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:604"/>
            <criterion comment="Patch DirectX82-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:603"/>
          </criteria>
          <criteria operator="AND" comment="DirectX 9.0 without DirectX9-KB839643-x86-ENU.EXE Installed">
            <criterion comment="the version of dplayx.dll is less than 5.3.0.903" negate="false" test_ref="oval:org.mitre.oval:tst:602"/>
            <criterion comment="DirectX 9.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:601"/>
            <criterion comment="Patch DirectX90-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:600"/>
          </criteria>
          <criteria operator="OR" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed">
            <criteria operator="AND" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP Gold">
              <criterion comment="the version of dplayx.dll is less than 5.1.2600.148" negate="false" test_ref="oval:org.mitre.oval:tst:599"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:598"/>
              <criterion comment="the patch kb839643 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:597"/>
            </criteria>
            <criteria operator="AND" comment="DirectX 8.1 without WindowsXP-KB839643-x86-ENU.EXE Installed on XP SP1">
              <criterion comment="the version of dplayx.dll is less than 5.1.2600.1517" negate="false" test_ref="oval:org.mitre.oval:tst:596"/>
              <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:598"/>
              <criterion comment="the patch kb839643 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:597"/>
              <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:969"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:219" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0516"/>
        <description>Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-25T12:47:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-10T20:39:58.679-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:30.871-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3955"/>
          <criterion comment="x86" negate="false" test_ref="oval:org.mitre.oval:tst:3338"/>
          <criterion comment="Patch 118844-14 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3195"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="system is running in 64-bit mode" negate="false" test_ref="oval:org.mitre.oval:tst:3884"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2188" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Path MTU Discovery Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:51.442-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
          <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Enable Path MTU Discovery is Disabled" negate="true" test_ref="oval:org.mitre.oval:tst:2352"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2184" version="1" class="vulnerability">
      <metadata>
        <title>MSHTA Code Execution Vulnerability (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0063" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0063"/>
        <description>The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application Host (MSHTA), as demonstrated using a Microsoft Word document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-04T12:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.2800.1643" negate="false" test_ref="oval:org.mitre.oval:tst:606"/>
          <criterion comment="the patch  KB893086 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2542"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2183" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail Custom DNS Map Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0906"/>
        <description>Buffer overflow in Sendmail before 8.12.5, when configured to use a custom DNS map to query TXT records, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a malicious DNS server.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Removed &quot;Sendmail running&quot; configuration test.  Sendmail installs as SUID root">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-04-20T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        <criterion comment="Sendmail - root (SUNWsndmr) installed" negate="false" test_ref="oval:org.mitre.oval:tst:608"/>
        <criterion comment="Patch 113575-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:607"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:218" version="1" class="vulnerability">
      <metadata>
        <title>Integer Overflows in Windows NT DirectX MIDI Library (QUARTZ.DLL)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0346"/>
        <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of quartz.dll is less than 6.1.5.132" negate="false" test_ref="oval:org.mitre.oval:tst:2788"/>
        <criterion comment="Patch Q19696 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:217" version="2" class="vulnerability">
      <metadata>
        <title>Help and Support Center PCHealth System Buffer Overflow (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0711" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0711"/>
        <description>Stack-based buffer overflow in the PCHealth system in the Help and Support Center function in Windows XP and Windows Server 2003 allows remote attackers to execute arbitrary code via a long query in an HCP URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-18T12:00:00.000-04:00" comment="Windows 2000 replaced by check for Windows 2000 SP4 or earlier">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:15.602-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of itircl.dll is less than 5.2.3790.80" negate="false" test_ref="oval:org.mitre.oval:tst:2792"/>
          <criterion comment="Patch KB825119 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2791"/>
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HCP Protocol" negate="true" test_ref="oval:org.mitre.oval:tst:2789"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2166" version="3" class="vulnerability">
      <metadata>
        <title>Windows NT Windows POSIX Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>POSIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0210"/>
        <description>The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-24T23:42:00.000-04:00" comment="Fixed typo in obj:503, referenced by tst:609.  Was 'Subsystem' instead of 'SubSystems'.  Fix implemented by Matthew Wojcik of MITRE.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-09-24T23:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-10T20:39:57.329-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:51.200-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="the patch kb841872 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:612"/>
          <criteria operator="OR" comment="Version check for psxss.exe on NT Workstation, Server 4.0 and NT Terminal Server">
            <criteria operator="AND" comment="This is an NT Terminal Server and the version of psxss.exe is less than 4.0.1381.33567">
              <criterion comment="the version of psxss.exe is less than 4.0.1381.33567" negate="false" test_ref="oval:org.mitre.oval:tst:611"/>
              <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            </criteria>
            <criteria operator="AND" comment="The version of psxss.exe is less than 4.0.1381.7269 on either NT Workstation or NT Server 4.0">
              <criteria operator="OR" comment="This is an NT Workstation or Windows NT Server 4.0 is installed">
                <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
                  <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
                  <criteria operator="OR" comment="Windows NT server product option">
                    <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
                    <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
                  </criteria>
                </criteria>
                <criterion comment="this is an NT Workstation" negate="false" test_ref="oval:org.mitre.oval:tst:2703"/>
              </criteria>
              <criterion comment="the version of psxss.exe is less than 4.0.1381.7269" negate="false" test_ref="oval:org.mitre.oval:tst:610"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="POSIX is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:609"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2163" version="1" class="vulnerability">
      <metadata>
        <title>Samba call_trans2open() Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0201"/>
        <description>Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Samba (SUNWsmbar) installed" negate="false" test_ref="oval:org.mitre.oval:tst:615"/>
          <criterion comment="Patch 114684-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:614"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criteria operator="AND" comment="Inetd running and inetd.conf contains smbd">
            <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
            <criterion comment="" negate="false" test_ref="oval:org.mitre.oval:tst:613"/>
          </criteria>
          <criterion comment="smbd running" negate="false" test_ref="oval:org.mitre.oval:tst:912"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:216" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP4 Bitmap Integer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0566" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0566"/>
        <description>Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:21:00.000-04:00" comment="modified wft-279 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3819.300" negate="false" test_ref="oval:org.mitre.oval:tst:2793"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2155" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 HtmlHelp Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0201"/>
        <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:215" version="1" class="vulnerability">
      <metadata>
        <title>KDM Weak Cookie Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0692" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0692"/>
        <description>KDM in KDE 3.1.3 and earlier uses a weak session cookie generation algorithm that does not provide 128 bits of entropy, which allows attackers to guess session cookies via brute force methods and gain access to the user session.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdebase version is less than 3.1-15" negate="false" test_ref="oval:org.mitre.oval:tst:2826"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/kdm is executable">
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2825"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2824"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2139" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos 5 ASN.1 Library DoS</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Kerberos5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0644" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0644"/>
        <description>The asn1buf_skiptail function in the ASN.1 decoder library for MIT Kerberos 5 (krb5) 1.2.2 through 1.3.4 allows remote attackers to cause a denial of service (infinite loop) via a certain BER encoding.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed kerberos unknown test to solaris file contents test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:616"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2137" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v5.5,SP2 Malformed Email Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0215"/>
        <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-26T08:06:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-26T08:14:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
          <criterion comment="the version of inetcomm.dll is less than 5.50.4942.400" negate="false" test_ref="oval:org.mitre.oval:tst:617"/>
          <criterion comment="the patch kb823353 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:668"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="all users have the preview pane disabled" negate="false" test_ref="oval:org.mitre.oval:tst:667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:213" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Messenger Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Messenger Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0717" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0717"/>
        <description>The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-03-29T12:00:00.000-04:00" comment="Fixed an error in the configuration section, now correctly testing that messenger service is enabled.  Before it was testing that HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Messenger\Start=2, now it is testing that it does not equal 4.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of msgsvc.dll is less than 5.0.2195.6861" negate="false" test_ref="oval:org.mitre.oval:tst:2798"/>
          <criterion comment="the version of wkssvc.dll is less than 5.0.2195.6861" negate="false" test_ref="oval:org.mitre.oval:tst:2797"/>
          <criterion comment="the patch q828035 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2796"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the messenger service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2795"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2128" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2003/64-bit XP Indexing Service Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Indexing Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0897" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0897"/>
        <description>The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
        <criterion comment="Indexing Service ciodm.dll is less than 5.2.3790.220" negate="false" test_ref="oval:org.mitre.oval:tst:619"/>
        <criterion comment="the patch Windows 2003 KB871250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:618"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:212" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2114" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Enhanced Metafile Image Format Rendering Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Enhanced Metafile (EMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0209"/>
        <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:11:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="the version of gdi32.dll is less than 5.0.2195.6945" negate="false" test_ref="oval:org.mitre.oval:tst:620"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:211" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:44.322-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:51.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_32606 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2108" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Certificate Validation Identity Spoofing Vulnerability (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1183"/>
        <description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false" test_ref="oval:org.mitre.oval:tst:1229"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2105" version="2" class="vulnerability">
      <metadata>
        <title>Word 2002 Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:15.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.6754.0" negate="false" test_ref="oval:org.mitre.oval:tst:621"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2100" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4943.400" negate="false" test_ref="oval:org.mitre.oval:tst:2762"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:210" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS HTTP Redirect Error Message Cross-site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0075" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0075"/>
        <description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:518" version="2">
      <metadata>
        <title>Microsoft Project 2000, SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Project 2000, SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:48.768-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.303-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Project 2000 is installed" test_ref="oval:org.mitre.oval:tst:77"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:21" version="2">
      <metadata>
        <title>Microsoft Office Remote Code Execution Using a Malformed GIF Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-0007" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0007" source="CVE"/>
        <description>Buffer overflow in GIFIMP32.FLT, as used in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted GIF image that triggers memory corruption when it is parsed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:15.158-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.386-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="vulnerable applications" operator="OR">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Project 2002, SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <extend_definition comment="Microsoft Project 2000, SP1 is installed" definition_ref="oval:org.mitre.oval:def:518"/>
        </criteria>
        <criterion comment="the version of Gifimp32.flt is less than 2003.1100.8020.0" test_ref="oval:org.mitre.oval:tst:67"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2094" version="1" class="vulnerability">
      <metadata>
        <title>BIND DoS via SIG RR Elements</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1221" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1221"/>
        <description>BIND 8.x through 8.3.3 allows remote attackers to cause a denial of service (crash) via SIG RR elements with invalid expiry times, which are removed from the internal BIND database and later cause a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Internet Domain Name Server (BIND, SUNWinamd) installed" negate="false" test_ref="oval:org.mitre.oval:tst:2626"/>
          <criterion comment="Patch 106938-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:623"/>
          <criterion comment="Patch 109326-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:622"/>
          <criterion comment="Patch 112970-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2625"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:209" version="1" class="vulnerability">
      <metadata>
        <title>SNMP Agent Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0053"/>
        <description>Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request.  NOTE: this candidate may be split or merged with other candidates.  This and other PROTOS-related candidates, especially CVE-2002-0012 and CVE-2002-0013, will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2077" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Content Advisor Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0555"/>
        <description>Buffer overflow in the Content Advisor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a crafted Content Advisor file, aka "Content Advisor Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1083"/>
          <criterion comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2073" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP3 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:42:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3821.2800" negate="false" test_ref="oval:org.mitre.oval:tst:625"/>
          <criterion comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:624"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:207" version="1" class="vulnerability">
      <metadata>
        <title>Scob and Toofer Internet Explorer v6.0,SP1 for Server 2003 Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549"/>
        <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T11:00:00.000-04:00" comment="modified wft-266 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.191" negate="false" test_ref="oval:org.mitre.oval:tst:2800"/>
          <criterion comment="the patch kb867801 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2799"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2068" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Word2000 Malformed Object Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2492"/>
        <description>Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:44.120-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:50.670-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8943" negate="false" test_ref="oval:org.mitre.oval:tst:626"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2065" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos Client Plaintext Password Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>pam_krb5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0653" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0653"/>
        <description>Solaris 9, when configured as a Kerberos client with patch 112908-12 or 115168-03 and using pam_krb5 as an "auth" module with the debug feature enabled, records passwords in plaintext, which could allow local users to gain other user's passwords by reading log files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed all unknown tests to solaris file contents tests">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criterion comment="Patch 112908-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:630"/>
          <criterion comment="Patch 112908-12 installed" negate="false" test_ref="oval:org.mitre.oval:tst:629"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:628"/>
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
          <criterion comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" negate="false" test_ref="oval:org.mitre.oval:tst:627"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2062" version="1" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (64-bit XP, SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.1.2600.1597" negate="false" test_ref="oval:org.mitre.oval:tst:631"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2061" version="2" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:43.978-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:50.253-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of rasmans.dll is less than 5.1.2600.1842" negate="false" test_ref="oval:org.mitre.oval:tst:671"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2060" version="2" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:43.858-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:49.854-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.529" negate="false" test_ref="oval:org.mitre.oval:tst:714"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:206" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.01,SP2 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3063"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3532.300" negate="false" test_ref="oval:org.mitre.oval:tst:2803"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:205" version="2" class="vulnerability">
      <metadata>
        <title>MS Outlook (Word 2000) RTF/HTML Script Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1056" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1056"/>
        <description>Microsoft Outlook 2000 and 2002, when configured to use Microsoft Word as the email editor, does not block scripts that are used while editing email messages in HTML or Rich Text Format (RTF), which could allow remote attackers to execute arbitrary scripts via an email that the user forwards or replies to.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-06T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-08T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-486 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:14.470-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.6328" negate="false" test_ref="oval:org.mitre.oval:tst:2804"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2046" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb890047.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
          <criterion comment="the version of shell32.dll is less than 5.0.3900.7009" negate="false" test_ref="oval:org.mitre.oval:tst:632"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2043" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Object Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0550"/>
        <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false" test_ref="oval:org.mitre.oval:tst:2738"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:204" version="1" class="vulnerability">
      <metadata>
        <title>IE ActiveX Popup Zone Restriction Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0838" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0838"/>
        <description>Internet Explorer allows remote attackers to bypass zone restrictions to inject and execute arbitrary programs by creating a popup window and inserting ActiveX object code with a "data" tag pointing to the malicious code, which Internet Explorer treats as HTML or Javascript, but later executes as an HTA application, a different vulnerability than CVE-2003-0532, and as exploited using the QHosts Trojan horse (aka Trojan.Qhosts, QHosts-1, VBS.QHOSTS, or aolfix.exe).</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          </criteria>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1264" negate="false" test_ref="oval:org.mitre.oval:tst:2918"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            </criteria>
          </criteria>
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2035" version="2" class="vulnerability">
      <metadata>
        <title>Exchange 2003,SP1 Calendar Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0027"/>
        <description>Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:43.717-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2003,SP1 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1108"/>
        <criterion comment="cdoex.dll is less than 6.5.7233.69" negate="false" test_ref="oval:org.mitre.oval:tst:633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2030" version="2" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:43.570-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:49.437-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:1132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:203" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Frames Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1187" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1187"/>
        <description>Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the &lt;frame> or &lt;iframe> element and javascript, aka "Frames Cross Site Scripting," as demonstrated using the PrivacyPolicy.dlg resource.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-03-09T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2025" version="1" class="vulnerability">
      <metadata>
        <title>System V login Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>login</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0797" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0797"/>
        <description>Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary commands via a large number of arguments through services such as telnet and rlogin.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7 or 8 installed">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        </criteria>
        <criterion comment="Patch 112300-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:635"/>
        <criterion comment="Patch 111085-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:634"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2024" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Execution in Mail When Forwarding In-line</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0884" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0884"/>
        <description>The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:43.338-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2023" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CVE-2006-1531)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1531"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:43.142-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird 1.5 is installed without an upgraded Firefox (1.5.0.2)">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2022" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Kernel Debugger-based Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" negate="false" test_ref="oval:org.mitre.oval:tst:2886"/>
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2020" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Accessing XBL Compilation Scope via valueOf.call()</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1733" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1733"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protect the compilation scope of privileged built-in XBL bindings, which allows remote attackers to execute arbitrary code via the (1) valueOf.call or (2) valueOf.apply methods of an XBL binding, or (3) "by inserting an XBL method into the DOM's document.body prototype chain."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:42.962-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:202" version="2" class="vulnerability">
      <metadata>
        <title>Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1143"/>
        <description>Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-478 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:13.260-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.6926" negate="false" test_ref="oval:org.mitre.oval:tst:2805"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2018" version="2" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:42.829-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:49.041-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.2709" negate="false" test_ref="oval:org.mitre.oval:tst:760"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2017" version="2" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:42.693-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:48.660-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2016" version="1" class="vulnerability">
      <metadata>
        <title>MS Exchange Server Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Outlook Web Access</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0203" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0203"/>
        <description>Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-08-25T12:24:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Exchange 5.5 with SP4 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2492"/>
          <criterion comment="the version of cdo.dll is less than 5.5.2558.10" negate="false" test_ref="oval:org.mitre.oval:tst:638"/>
          <criterion comment="the  patch kb842436 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:637"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Outlook Web Access exists" negate="false" test_ref="oval:org.mitre.oval:tst:636"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2011" version="1" class="vulnerability">
      <metadata>
        <title>ISC BIND Cache Poison Denial Of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Bind</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0914" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0914"/>
        <description>ISC BIND 8.3.x before 8.3.7, and 8.4.x before 8.4.3, allows remote attackers to poison the cache via a malicious name server that returns negative responses with a large TTL (time-to-live) value.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified sat-10 - Changed test to pattern match to check for 64bit version of Core Solaris">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified sat-10 - Changed regular expression to properly check for 64bit package">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-01-24T02:36:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 106938-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:642"/>
          <criterion comment="Patch 109326-13 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:641"/>
          <criterion comment="Patch 112970-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:640"/>
          <criterion comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:639"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="in.named running" negate="false" test_ref="oval:org.mitre.oval:tst:2624"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:201" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP ComboBox/ListBox GUI Widget User32.dll Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0659"/>
        <description>Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-28T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T12:00:00.000-04:00" comment="The compound test that includes a check for SP1 or earlier has been added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Added patch KB891711 (from MS05-002) which supercedes the previous patch">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-28T09:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T07:32:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of user32.dll exists">
            <criteria operator="AND" comment="no service pack is installed and user32.dll is less than 5.1.2600.118">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of user32.dll is less than 5.1.2600.118" negate="false" test_ref="oval:org.mitre.oval:tst:2810"/>
            </criteria>
            <criteria operator="AND" comment="service pack 1 is installed and user32.dll is less than 5.1.2600.1255">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of user32.dll is less than 5.1.2600.1255" negate="false" test_ref="oval:org.mitre.oval:tst:2809"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb824141 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2808"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
          <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the utility manager Service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2806"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2009" version="2" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:42.563-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:48.185-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2008" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-154 - wft-154 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" negate="false" test_ref="oval:org.mitre.oval:tst:678"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2007" version="2" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:42.432-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:47.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.1.2600.1836" negate="false" test_ref="oval:org.mitre.oval:tst:657"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2003" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft JScript Memory Corruption Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:42.312-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:47.362-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the version of Jscript.dll is less than 5.6.0.8831" negate="false" test_ref="oval:org.mitre.oval:tst:1206"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2002" version="2" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in Kerberos 5 (krb5_aname_to_localname)</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0523" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0523"/>
        <description>Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-13T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="Changed two unknown tests for kerberos configuration to Solaris text file contents tests">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:12.225-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Kerberos 5 installed" negate="false" test_ref="oval:org.mitre.oval:tst:648"/>
          <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 112908-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:647"/>
          <criterion comment="Patch 112536-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:646"/>
          <criteria operator="AND" comment="Patches 112237-11 and 112390-09 or greater installed" negate="true">
            <criterion comment="Patch 112237-11 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:645"/>
            <criterion comment="Patch 112390-09 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:644"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
          <criterion comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" negate="false" test_ref="oval:org.mitre.oval:tst:643"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:200" version="2" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Windows Script Engine for JScript v5.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-03T12:00:00.000-04:00" comment="Corrected to reflect the unification of the Windows Schema">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if active scripting is enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-08-24T10:58:00.000-04:00" comment="Added Patch to Definition">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-08-24T10:58:00.000-04:00" comment="negated patch">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:11.933-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of jscript.dll is less than 5.6.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2905"/>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the patch js56nen.exe (5.6.0.8513 version) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2904"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="active scripting is enabled">
            <criteria operator="AND" comment="current user settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and active scripting is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:20" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed OVAL20</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of rpcss.dll is less than 5.0.2195.6810" negate="false" test_ref="oval:org.mitre.oval:tst:3083"/>
        <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2" version="1" class="vulnerability">
      <metadata>
        <title>Mutt BO Vulnerability in balsa</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Mutt</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0140" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0140"/>
        <description>Buffer overflow in Mutt 1.4.0 and possibly earlier versions, 1.5.x up to 1.5.3, and other programs that use Mutt code such as Balsa before 2.0.10, allows a remote malicious IMAP server to cause a denial of service (crash) and possibly execute arbitrary code via a crafted folder.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="balsa version is less than 2.0.6-2" negate="false" test_ref="oval:org.mitre.oval:tst:3151"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/balsa is executable">
            <criterion comment="/usr/bin/balsa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:3150"/>
            <criterion comment="/usr/bin/balsa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:3149"/>
            <criterion comment="/usr/bin/balsa is executable" negate="false" test_ref="oval:org.mitre.oval:tst:3148"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1997" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Negotiate Security Software Provider Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Negotiate SSP interface</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0119"/>
        <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-19T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2004-07-20T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-11T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:38:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-07T18:56:00.000-04:00" comment="set negate attribute to true in criteria for oval:org.mitre.oval:tst:2845">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-07T18:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:11.650-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="OR" comment="Version checks on XP for Ipnathlp.dll">
            <criteria operator="AND" comment="No service pack is installed and the version of Ipnathlp.dll is less than 5.1.2600.137">
              <criterion comment="The version of Ipnathlp.dll is less than 5.1.2600.137" negate="false" test_ref="oval:org.mitre.oval:tst:650"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            </criteria>
            <criteria operator="AND" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364 and windows service pack 1 is installed">
              <criterion comment="The version of Ipnathlp.dll is less than 5.1.2600.1364" negate="false" test_ref="oval:org.mitre.oval:tst:649"/>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            </criteria>
            <criteria operator="AND" comment="64 bit version of windows with service pack 1 installed and the version of Ipnathlp.dll is less than 5.1.2600.1364">
              <criteria operator="AND" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364 and windows service pack 1 is installed">
                <criterion comment="The version of Ipnathlp.dll is less than 5.1.2600.1364" negate="false" test_ref="oval:org.mitre.oval:tst:649"/>
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              </criteria>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Negotiate is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:709"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1996" version="2" class="vulnerability">
      <metadata>
        <title>Exchange 2003,SP2 Calendar Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0027"/>
        <description>Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:42.184-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2003,SP2 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1202"/>
        <criterion comment="cdoex.dll is less than 6.5.7650.29" negate="false" test_ref="oval:org.mitre.oval:tst:651"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1990" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Denial of Service Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1184"/>
        <description>Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:41.999-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Msdtctm.dll is less than 2000.2.3535.0" negate="false" test_ref="oval:org.mitre.oval:tst:1074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:199" version="1" class="vulnerability">
      <metadata>
        <title>Weak Encryption in RDP Protocol</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Data Protocol (RDP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0863" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0863"/>
        <description>Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Terminal Server Version" negate="false" test_ref="oval:org.mitre.oval:tst:2816"/>
          <criterion comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" negate="false" test_ref="oval:org.mitre.oval:tst:2815"/>
          <criterion comment="Patch Q324380 installed" negate="true" test_ref="oval:org.mitre.oval:tst:2814"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="RDP Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2813"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1987" version="2" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in Flash Player 6&amp;7 (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2628"/>
        <description>Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:41.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Swflash.ocx is the original shipped with XP,SP1" negate="false" test_ref="oval:org.mitre.oval:tst:676"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1985" version="2" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:41.748-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:46.973-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1984" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft PowerPoint 2000 Remote Code Execution Using a Malformed Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0022"/>
        <description>Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 649 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:41.602-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:46.538-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="PowerPoint 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:861"/>
        <criterion comment="the version of PowerPnt.exe is less than 9.0.0.8942" negate="false" test_ref="oval:org.mitre.oval:tst:652"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1983" version="2" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:41.454-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:46.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of rasmans.dll is less than 5.2.3790.529" negate="false" test_ref="oval:org.mitre.oval:tst:757"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1982" version="1" class="vulnerability">
      <metadata>
        <title>Apache Connection Blocking Denial Of Service Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0174"/>
        <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T01:13:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <modified date="2004-10-18T03:12:00.000-04:00" comment="Changed apache test to file test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2004-10-19T11:17:00.000-04:00" comment="Changed apache test to package test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Patch 116973-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:656"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:655"/>
          <criterion comment="Apache (SUNWapchu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:653"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:198" version="1" class="vulnerability">
      <metadata>
        <title>Automatic ActiveX Approval on Windows 2000 Low Memory</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0660"/>
        <description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" negate="false" test_ref="oval:org.mitre.oval:tst:2817"/>
          <criterion comment="Patch WindowsXP-KB823182-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2841"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="downloading of signed ActiveX controls is enabled">
            <criteria operator="AND" comment="current user settings are being used and the downloading of signed ActiveX controls is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="downloading of signed ActiveX controls is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2840"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and the downloading of signed ActiveX controls is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="downloading of signed ActiveX controls is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2839"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1979" version="2" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:41.326-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:45.704-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.1.2600.1836" negate="false" test_ref="oval:org.mitre.oval:tst:657"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1977" version="2" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:41.143-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:45.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1976" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Table Conversion Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Replaced all criteria. 1) Included all XP,64 versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false" test_ref="oval:org.mitre.oval:tst:2570"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1975" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Mail Multiple Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1045"/>
        <description>The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:40.983-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1974" version="2" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v10.0 on S03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:40.815-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:44.903-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Windows Media Player 10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:833"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of wmp.dll is less than 10.0.0.3704" negate="false" test_ref="oval:org.mitre.oval:tst:658"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1973" version="2" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:40.654-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:44.453-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1970" version="1" class="vulnerability">
      <metadata>
        <title>Off-by-one Error in fb_realpath()</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Solaris Management Console (SMC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0466" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0466"/>
        <description>Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="FTP Server - Usr (SUNWftpu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:661"/>
          <criterion comment="Patch 114564-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:660"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains in.ftpd" negate="false" test_ref="oval:org.mitre.oval:tst:659"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:197" version="1" class="vulnerability">
      <metadata>
        <title>IIS ISAPI Extension Indexing Service Buffer Overflow (Code Red)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0500" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0500"/>
        <description>Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier allows remote attackers to execute arbitrary commands via a long argument to Internet Data Administration (.ida) and Internet Data Query (.idq) files such as default.ida, as commonly exploited by Code Red.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-08-04T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" negate="false" test_ref="oval:org.mitre.oval:tst:2820"/>
          <criterion comment="Patch Q300972 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2819"/>
          <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Windows 2000 Security Roll-up 1 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2990"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="idq.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:2818"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1968" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Security Check of js_ValueToFunctionObject() Can Be Circumvented</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1726" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1726"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueToFunctionObject check and execute arbitrary code via unknown vectors involving setTimeout and Firefox' ForEach method.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:40.478-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1964" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP (32-Bit) Task Scheduler Stack Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Task Scheduler</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0212"/>
        <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="added compound tests">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-07T18:56:00.000-04:00" comment="set negate attribute to true in criteria for oval:org.mitre.oval:tst:2845">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-07T18:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:09.176-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="OR" comment="Affected mstask.dll file versions based on service pack levels">
          <criteria operator="AND" comment="no service pack is installed and mstask.dll is less than 5.1.2600.155">
            <criterion comment="the version of mstask.dll is less than 5.1.2600.155" negate="false" test_ref="oval:org.mitre.oval:tst:663"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
          </criteria>
          <criteria operator="AND" comment="service pack 1 is installed and mstask.dll is less than 5.1.2600.1564">
            <criterion comment="the version of mstask.dll is less than 5.1.2600.1564" negate="false" test_ref="oval:org.mitre.oval:tst:662"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:720"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1963" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP IE HTML Help ActiveX control Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1043"/>
        <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="the patch kb890175 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:972"/>
          <criteria operator="OR" comment="A vulnerable version of hhctrl.ocx exists on Windows XP">
            <criteria operator="AND" comment="Windows XP SP1 or earlier and version of hhctrl.ocx is less than 5.2.3790.233">
              <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
              <criterion comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false" test_ref="oval:org.mitre.oval:tst:971"/>
            </criteria>
            <criteria operator="AND" comment="Windows XP SP2 or later and version of hhctrl.ocx is less than 5.2.3790.1280">
              <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2837"/>
              <criterion comment="the version of hhctrl.ocx is less than 5.2.3790.1280" negate="false" test_ref="oval:org.mitre.oval:tst:664"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1962" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Negotiate Security Software Provider Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Negotiate Security Software Provider</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0119"/>
        <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and 64-bit or 32-bit version of Windows is installed">
            <criteria operator="AND" comment="The version of ipnathlp.dll is less than 5.2.3790.142 and a 64 bit version of Windows is installed">
              <criterion comment="The version of ipnathlp.dll is less than 5.2.3790.142" negate="false" test_ref="oval:org.mitre.oval:tst:665"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criteria operator="AND" comment="The version of Ipnathlp.dll is less than 5.2.3790.142 and a 32-bit version of Windows is installed">
              <criterion comment="The version of ipnathlp.dll is less than 5.2.3790.142" negate="false" test_ref="oval:org.mitre.oval:tst:665"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Negotiate is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:709"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1961" version="2" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability(64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:40.348-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:44.014-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:196" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:40.215-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:43.584-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33159 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1959" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Table Conversion Vulnerability (32-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-01T12:00:00.000-04:00" comment="modified wft-123 - Changed/Corrected literal path">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-123 - wft-123 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) dropped version checks on mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of wordpad.exe is less than 5.1.2600.1606" negate="false" test_ref="oval:org.mitre.oval:tst:666"/>
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1955" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site Scripting Using .valueOf.call()</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1731" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1731"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:39.953-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1950" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6,SP1 Malformed Email Header Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0215"/>
        <description>Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-26T08:05:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-08-26T08:14:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
          <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1441" negate="false" test_ref="oval:org.mitre.oval:tst:669"/>
          <criterion comment="the patch kb823353 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:668"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="all users have the preview pane disabled" negate="true" test_ref="oval:org.mitre.oval:tst:667"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:195" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 KCMS Arbitrary File Access Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>kcms_server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0027"/>
        <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File kcms_server exists" negate="false" test_ref="oval:org.mitre.oval:tst:2931"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains kcms_server" negate="false" test_ref="oval:org.mitre.oval:tst:2930"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File kcms_server executable and SUID or SGID">
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2929"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2928"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1949" version="2" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:39.825-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:43.166-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1947" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CVE-2006-1529)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1529" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1529"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:39.642-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird 1.5 is installed without an upgraded Firefox (1.5.0.2)">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1944" version="2" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:39.465-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:42.685-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1943" version="1" class="vulnerability">
      <metadata>
        <title>IE .chm Directory Traversal Windows 2000 Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1041"/>
        <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bugmay overlap CVE-2004-0475.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1942" version="2" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:39.345-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:42.082-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.1.2600.2902" negate="false" test_ref="oval:org.mitre.oval:tst:692"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:194" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT RPCSS DCOM Buffer Overflow (Blaster, Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0352" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0352"/>
        <description>Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:53:00.000-04:00" comment="modified wft-567 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Patch Q823980 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2822"/>
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of rpcss.dll is less than 4.0.1381.7224" negate="false" test_ref="oval:org.mitre.oval:tst:2821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1936" version="2" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:39.216-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:41.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of rasmans.dll is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:836"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1931" version="2" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:39.087-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:41.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:193" version="1" class="vulnerability">
      <metadata>
        <title>KDM pam_setcred Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>KDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0690" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0690"/>
        <description>KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-21T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="kdebase version is less than 3.1-15" negate="false" test_ref="oval:org.mitre.oval:tst:2826"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/kdm is executable">
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2825"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2824"/>
            <criterion comment="/usr/bin/kdm is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2823"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1929" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla File Stealing by Changing Input Type</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1729" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1729"/>
        <description>Mozilla Firefox 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to read arbitrary files by (1) inserting the target filename into a text box, then turning that box into a file upload control, or (2) changing the type of y that is associated with an event handler.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:38.831-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1928" version="2" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:38.672-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:40.801-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1924" version="2" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:38.543-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:40.378-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1922" version="2" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in Flash Player 8 (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0024"/>
        <description>Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:38.416-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Flash.ocx is less than 7.0.19.0" negate="false" test_ref="oval:org.mitre.oval:tst:859"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:192" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE ToolTalk Database Heap Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0679"/>
        <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 110286-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2827"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1918" version="2" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:38.287-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:39.981-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1916" version="2" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:38.150-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:39.569-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1914" version="2" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:37.921-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:39.060-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1912" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Denial of Service Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1184"/>
        <description>Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:37.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Msdtctm.dll is less than 2001.12.4414.311" negate="false" test_ref="oval:org.mitre.oval:tst:670"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1911" version="2" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:37.622-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:38.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1910" version="2" class="vulnerability">
      <metadata>
        <title>WinXP Blind Connection Reset Attack Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:50.972-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
        <criteria operator="OR" comment="A vulnerable version of tcpip.sys is installed.">
          <criteria operator="AND" comment="Service Pack 1 is installed and tcpip.sys is less than 5.1.2600.1693">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1693" negate="false" test_ref="oval:org.mitre.oval:tst:776"/>
          </criteria>
          <criteria operator="AND" comment="Service Pack 2 is installed and tcpip.sys is less than 5.1.2600.2685">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2685" negate="false" test_ref="oval:org.mitre.oval:tst:775"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:191" version="1" class="vulnerability">
      <metadata>
        <title>IIS Web Server File Request Parsing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0886"/>
        <description>IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" negate="false" test_ref="oval:org.mitre.oval:tst:2828"/>
        <criterion comment="Patch Q277873 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3021"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
        <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3019"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1908" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Invalid Memory Access Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0034"/>
        <description>Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, aka the MSDTC Invalid Memory Access Vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:37.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Msdtctm.dll is less than 2001.12.4414.65" negate="false" test_ref="oval:org.mitre.oval:tst:1008"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1907" version="2" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:37.297-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:38.138-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of rasmans.dll is less than 5.1.2600.1842" negate="false" test_ref="oval:org.mitre.oval:tst:671"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1906" version="2" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:37.166-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:37.742-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1905" version="1" class="vulnerability">
      <metadata>
        <title>dtsession Buffer Overflow via HOME Envvar</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0092" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0092"/>
        <description>Heap-based buffer overflow in dtsession for Solaris 2.5.1 through Solaris 9 allows local users to gain root privileges via a long HOME environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
        <criterion comment="Patch 107702-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:674"/>
        <criterion comment="Patch 109354-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:673"/>
        <criterion comment="Patch 114497-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:672"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1904" version="2" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:36.973-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:37.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.0.2195.7097" negate="false" test_ref="oval:org.mitre.oval:tst:685"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1903" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CVE-2006-1530)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1530" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1530"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:36.803-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird 1.5 is installed without an upgraded Firefox (1.5.0.2)">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1901" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CVE-2006-1724)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1724"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:36.624-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:190" version="1" class="vulnerability">
      <metadata>
        <title>ActiveX Certificate Enrollment Unauthorized Remote Certificate Deletion</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Certificate Enrollment Control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0699" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0699"/>
        <description>Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of xenroll.dll is less than 5.131.3659.0" negate="false" test_ref="oval:org.mitre.oval:tst:2831"/>
          <criterion comment="Patch Q323172 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2830"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="ActiveX Enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX Enabled In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:2829"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:19" version="2" class="vulnerability">
      <metadata>
        <title>IE Cross-Site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0189"/>
        <description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the "Cross-Site Scripting in Local HTML Resource" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:04.771-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2716.2200" negate="false" test_ref="oval:org.mitre.oval:tst:3086"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="true">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1894" version="2" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in Flash Player 8 (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0024"/>
        <description>Multiple unspecified vulnerabilities in Adobe Flash Player 8.0.22.0 and earlier allow remote attackers to execute arbitrary code via a crafted SWF file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:36.489-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Swflash.ocx is the original shipped with XP,SP1" negate="false" test_ref="oval:org.mitre.oval:tst:676"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1891" version="2" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:36.356-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:36.925-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:189" version="1" class="vulnerability">
      <metadata>
        <title>Network Share Provider Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0724" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0724"/>
        <description>Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:55:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of xactsrv.dll is less than 5.0.2195.5971" negate="false" test_ref="oval:org.mitre.oval:tst:2834"/>
          <criterion comment="Patch Q326830 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2833"/>
          <criterion comment="SP4 or later Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Lanman enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2832"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1889" version="1" class="vulnerability">
      <metadata>
        <title>SMB Code Execution Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0045"/>
        <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-03-29T08:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.1.2600.1620" negate="false" test_ref="oval:org.mitre.oval:tst:677"/>
        <criterion comment="the patch KB885250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1888" version="1" class="vulnerability">
      <metadata>
        <title>LSASS Privilege Escalation Vulnerability (64-bit Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Local Security Authority Subsystem Service (LSASS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0894" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0894"/>
        <description>LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false" test_ref="oval:org.mitre.oval:tst:842"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1887" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site Scripting through window.controllers</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1732" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1732"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to bypass same-origin protections and conduct cross-site scripting (XSS) attacks via unspecified vectors involving the window.controllers array.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:36.188-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1886" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (32-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-154 - wft-154 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" negate="false" test_ref="oval:org.mitre.oval:tst:678"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1881" version="2" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:36.024-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:36.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1880" version="1" class="vulnerability">
      <metadata>
        <title>CDE dtspcd Daemon Symlink Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>dtspcd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0689"/>
        <description>The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criterion comment="CDE Daemons (SUNWdtdmn) installed" negate="false" test_ref="oval:org.mitre.oval:tst:680"/>
        <criterion comment="Patch 108221-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:679"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:188" version="2" class="vulnerability">
      <metadata>
        <title>MS Word Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0664"/>
        <description>Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-08-25T10:31:00.000-04:00" comment="Added word 2000 and winword.exe information">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-470 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:03.613-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.7924" negate="false" test_ref="oval:org.mitre.oval:tst:2835"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1872" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Enhanced Metafile Image Format Rendering Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Enhanced Metafile (EMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0209"/>
        <description>Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats that involve "an unchecked buffer."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T09:59:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="the version of vdmdbg.dll is less than 5.1.2600.1560" negate="false" test_ref="oval:org.mitre.oval:tst:681"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1866" version="2" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:35.894-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:36.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criteria operator="OR" comment="Either jgdw400.dll or Wjgdw400.dll exist with a file version less than 106.0.0.0">
          <criterion comment="the version of jgdw400.dll is less than 106.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:835"/>
          <criterion comment="the version of Wjgdw400.dll is less than 106.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:782"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1862" version="2" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:35.662-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:35.595-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1857" version="2" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:35.404-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:35.183-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of rasmans.dll is less than 5.0.2195.7093" negate="false" test_ref="oval:org.mitre.oval:tst:747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1855" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site JavaScript Injection Using Event Handlers</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1741" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1741"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:35.230-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1852" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Terminal Server Unchecked Buffer in NetDDE</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>NetDDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0206"/>
        <description>Network Dynamic Data Exchange (NetDDE) services for Microsoft Windows 98, Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows attackers to remotely execute arbitrary code or locally gain privileges via a malicious message or application that involves an "unchecked buffer," possibly a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T04:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="the version of nddenb32.dll is less than 4.0.1381.33565" negate="false" test_ref="oval:org.mitre.oval:tst:684"/>
        <criterion comment="the version of netdde.exe is less than 4.0.1381.33574" negate="false" test_ref="oval:org.mitre.oval:tst:683"/>
        <criterion comment="the patch KB841533 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:682"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1851" version="2" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:35.099-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:34.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of rasmans.dll is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:836"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1850" version="2" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:34.163-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.0.2195.7097" negate="false" test_ref="oval:org.mitre.oval:tst:685"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:185" version="1" class="vulnerability">
      <metadata>
        <title>Automatic ActiveX Approval on WinXP Low Memory</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Authenticode</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0660" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0660"/>
        <description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2004-03-05T12:00:00.000-04:00" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T10:18:00.000-04:00" comment="The compound test that includes SP1 or earlier has been added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-09-13T10:18:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of cryptui.dll exists">
            <criteria operator="AND" comment="no service pack is installed and cryptui.dll is less than 5.131.2600.117">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of cryptui.dll is less than 5.131.2600.117" negate="false" test_ref="oval:org.mitre.oval:tst:2844"/>
            </criteria>
            <criteria operator="AND" comment="service pack 1 is installed and cryptui.dll is less than 5.131.2600.1243">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of cryptui.dll is less than 5.131.2600.1243" negate="false" test_ref="oval:org.mitre.oval:tst:2842"/>
            </criteria>
          </criteria>
          <criterion comment="Patch WindowsXP-KB823182-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2841"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="downloading of signed ActiveX controls is enabled">
            <criteria operator="AND" comment="current user settings are being used and the downloading of signed ActiveX controls is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="downloading of signed ActiveX controls is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2840"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and the downloading of signed ActiveX controls is enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="downloading of signed ActiveX controls is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2839"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1848" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Mozilla Firefox Tag Order Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0749" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0749"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors involving a "particular sequence of HTML tags" that leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:34.648-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1847" version="1" class="vulnerability">
      <metadata>
        <title>SMB Code Execution Vulnerability (Server 2003 / 64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0045"/>
        <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T10:39:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.252" negate="false" test_ref="oval:org.mitre.oval:tst:686"/>
        <criterion comment="the patch KB885250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:824"/>
        <criteria operator="OR" comment="Windows Server 2003 32-bit OR 64-bit OR Windows XP 64-bit Version 2003 is installed">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1846" version="2" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.522-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:33.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of rasmans.dll is less than 5.1.2600.2908" negate="false" test_ref="oval:org.mitre.oval:tst:705"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1845" version="2" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (Win2k)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.389-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:33.395-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1844" version="1" class="vulnerability">
      <metadata>
        <title>ypbind Daemon Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>NIS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-1328" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1328"/>
        <description>Buffer overflow in ypbind daemon in Solaris 5.4 through 8 allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criterion comment="NIS/NIS+ Utilities installed (SUNWnisu)" negate="false" test_ref="oval:org.mitre.oval:tst:690"/>
          <criterion comment="Patch 108750-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:689"/>
          <criterion comment="Patch 110322-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:688"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ypbind running" negate="false" test_ref="oval:org.mitre.oval:tst:687"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1843" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (32-Bit) Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criteria operator="OR" comment="a vulnerable version of grpconv.exe exists">
          <criteria operator="AND" comment="no service pack is installed and a vulnerable version of grpconv.exe exists">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of grpconv.exe is less than 5.1.2600.166" negate="false" test_ref="oval:org.mitre.oval:tst:691"/>
          </criteria>
          <criteria operator="AND" comment="service pack 1 is installed and a vulnerable version of grpconv.exe exists">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of grpconv.exe is less than 5.1.2600.1580" negate="false" test_ref="oval:org.mitre.oval:tst:702"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1842" version="2" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.256-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:33.011-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1841" version="2" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.134-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:32.598-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.1.2600.2902" negate="false" test_ref="oval:org.mitre.oval:tst:692"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1840" version="1" class="vulnerability">
      <metadata>
        <title>LDAP rootDN Password Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>LDAP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1782"/>
        <description>Unspecified vulnerability in Solaris 8 and 9 allows local users to obtain the LDAP Directory Server root Distinguished Name (rootDN) password when a privileged user (1) runs idsconfig; or "insecurely" runs LDAP2 commands with the -w option, including (2) ldapadd, (3) ldapdelete, (4) ldapmodify, (5) ldapmodrdn, and (6) ldapsearch.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-14T06:41:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 108993-14 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:700"/>
          <criterion comment="Patch 108993-51 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:699"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 115677-02 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:698"/>
          <criterion comment="Patch 121321-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:697"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 108994-14 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:696"/>
          <criterion comment="Patch 108994-51 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:695"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102113 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 115678-02 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:694"/>
          <criterion comment="Patch 121322-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:693"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:184" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:34.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:32.152-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33159 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1838" version="2" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:33.867-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:31.729-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1837" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) Program Group Converter Buffer Overflow in grpconv.exe</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:39:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criteria operator="OR" comment="a vulnerable version of grpconv.exe exists">
          <criterion comment="the version of grpconv.exe is less than 5.1.2600.1580" negate="false" test_ref="oval:org.mitre.oval:tst:702"/>
          <criterion comment="the version of grpconv.exe (syswow64) is less than 5.1.2600.1580" negate="false" test_ref="oval:org.mitre.oval:tst:701"/>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1836" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft PowerPoint 2002 Remote Code Execution Using a Malformed Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0022"/>
        <description>Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:553 (referenced by tst:703) fixed: owerpnt.exe to powerpnt.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:33.695-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:31.242-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="PowerPoint 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:704"/>
        <criterion comment="the version of PowerPnt.exe is less than 10.0.6800.0" negate="false" test_ref="oval:org.mitre.oval:tst:703"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1830" version="2" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:33.497-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:30.825-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:183" version="1" class="vulnerability">
      <metadata>
        <title>Apache IPv6 Socket Failure Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0254" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0254"/>
        <description>Apache 2 before 2.0.47, when running on an IPv6 host, allows attackers to cause a denial of service (CPU consumption by infinite loop) when the FTP proxy server fails to create an IPv6 socket.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.5" negate="false" test_ref="oval:org.mitre.oval:tst:2852"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1829" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (RegEx)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1737" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1737"/>
        <description>Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:33.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1827" version="2" class="vulnerability">
      <metadata>
        <title>SMB Invalid Handle Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2374" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2374"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows localusers to cause a denial of service (hang) via by calling the MrxSmbCscIoctlCloseForCopyChunk with the file handle of the shadow device, which results in a deadlock, aka the "SMB Invalid Handle Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:33.188-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:30.337-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:1132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1823" version="2" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (WinXP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:33.060-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:29.869-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of rasmans.dll is less than 5.1.2600.2908" negate="false" test_ref="oval:org.mitre.oval:tst:705"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1822" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 CSRSS Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Client Server Runtime System (CSRSS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0551"/>
        <description>Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false" test_ref="oval:org.mitre.oval:tst:1025"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1821" version="2" class="vulnerability">
      <metadata>
        <title>ActiveX Control Memory Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2383" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2383"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which causes Internet Explorer to crash in a way that enables the code execution.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.932-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:29.392-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1820" version="2" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v9.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.741-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:28.915-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:786"/>
        <criterion comment="Windows Media Player 10 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:833"/>
        <criterion comment="the version of wmp.dll is less than 9.0.0.3349" negate="false" test_ref="oval:org.mitre.oval:tst:706"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:182" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Heap Overrun in HTR Chunked Encoding</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0364"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" negate="false" test_ref="oval:org.mitre.oval:tst:2847"/>
          <criterion comment="Patch Q321599 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2846"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ism.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3057"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1818" version="2" class="vulnerability">
      <metadata>
        <title>Exchange 2000,SP4 Calendar Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0027"/>
        <description>Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:32.600-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2000,SP3 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:992"/>
        <criterion comment="cdoex.dll is less than 6.0.6618.4" negate="false" test_ref="oval:org.mitre.oval:tst:707"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1813" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (32-bit, SP1) RPCSS DCOM Buffer Overflow (Blaster)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.1.2600.1254" negate="false" test_ref="oval:org.mitre.oval:tst:708"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1811" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Secure-site Spoof (requires security warning dialog)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1740" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1740"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:32.430-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:181" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.283-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:28.466-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1808" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Negotiate Security Software Provider Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Negotiate SSP interface</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0119"/>
        <description>The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit request during authentication protocol selection.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-345 - Addded a space in the registry key component of the file path">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T01:26:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criterion comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:710"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Negotiate is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:709"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1807" version="2" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v8.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.163-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:28.028-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1035"/>
        <criterion comment="the version of wmpui.dll is less than 8.0.0.4496" negate="false" test_ref="oval:org.mitre.oval:tst:711"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1806" version="2" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:32.026-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:27.608-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1805" version="2" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v10.0, 64-bit)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.886-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:27.186-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:833"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of wwmp.dll is less than 10.0.0.3704" negate="false" test_ref="oval:org.mitre.oval:tst:712"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1800" version="2" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.754-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:26.731-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:180" version="2" class="vulnerability">
      <metadata>
        <title>Windows 2000,SP4 Remote Desktop Protocol (RDP) DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.531-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:26.291-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed" negate="false">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3381"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3652"/>
        </criteria>
        <criterion comment="rdpwd.sys is less than 5.0.2195.7055" negate="false" test_ref="oval:org.mitre.oval:tst:3633"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:18" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Shell Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0070"/>
        <description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <modified date="2004-09-16T12:00:00.000-04:00" comment="Completing an initial submission.">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-09-29T02:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-10-19T04:29:00.000-04:00" comment="done">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </modified>
            <status_change date="2004-10-27T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="the version of shell32.dll is less than 4.0.1381.7116" negate="false" test_ref="oval:org.mitre.oval:tst:3088"/>
        <criterion comment="Patch Q313829 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3087"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1795" version="2" class="vulnerability">
      <metadata>
        <title>Word 2003 Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:58.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of winword.exe is less than 11.0.6502.0" negate="false" test_ref="oval:org.mitre.oval:tst:713"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1793" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Malformed GIF Image Double-free Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1048"/>
        <description>Double-free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-02T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-26T12:19:00.000-04:00" comment="modified wft-268 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2743.600" negate="false" test_ref="oval:org.mitre.oval:tst:2583"/>
        <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1792" version="2" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.411-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:25.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.529" negate="false" test_ref="oval:org.mitre.oval:tst:714"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1791" version="2" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (S03,SP1) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:56.156-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false" test_ref="oval:org.mitre.oval:tst:1632"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1790" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Deleted Object Reference When designMode="on"</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1993"/>
        <description>Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object.  NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:31.241-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.3">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.42618 (v1.5.0.3)" negate="true" test_ref="oval:org.mitre.oval:tst:717"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.2 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:716"/>
          <criterion comment="Firefox version 1.5.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:715"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:179" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 LBXProxy Display Name Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>lbxproxy</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0090" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0090"/>
        <description>Buffer overflow in Low BandWidth X proxy (lbxproxy) in Solaris 8 allows local users to execute arbitrary code via a long display command line option.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File lbxproxy exists" negate="false" test_ref="oval:org.mitre.oval:tst:2964"/>
          <criterion comment="Patch 107654-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2848"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File lbxproxy SGID and executable">
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2962"/>
            <criterion comment="File lbxproxy SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:2961"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1788" version="2" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:31.104-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:25.471-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1787" version="2" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.933-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:25.059-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7087" negate="false" test_ref="oval:org.mitre.oval:tst:718"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1786" version="1" class="vulnerability">
      <metadata>
        <title>XPM Image Decoder Malicious Color String Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0783"/>
        <description>Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-21T04:03:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114644-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:817"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114645-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:816"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114686-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:815"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115738-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:813"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114687-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:812"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115739-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:811"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="JDS release 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:810"/>
          <criterion comment="Patch 121092-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1785" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft JScript Memory Corruption Vulnerability (Win2K w/ JScript 5.6)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.792-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:24.604-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Jscript.dll is greater than or equal to 5.6.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:719"/>
        <criterion comment="the version of Jscript.dll is less than 5.6.0.8831" negate="false" test_ref="oval:org.mitre.oval:tst:1206"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1783" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Script Execution Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1190"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1781" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-Bit) Task Scheduler Stack Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Task Scheduler</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0212"/>
        <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T10:03:00.000-04:00" comment="">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mstask.dll is less than 5.1.2600.1555" negate="false" test_ref="oval:org.mitre.oval:tst:721"/>
        <criterion comment="Patch Windows2000-kb841873-x86-enu.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:720"/>
        <criteria operator="AND" comment="Windows XP 64-bit with SP1 (or earlier) installed">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1780" version="2" class="vulnerability">
      <metadata>
        <title>Outlook Express 5.5 WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version  in ste:649.  Modified by Harvey Rubinovitz.">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:649 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:55.387-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 5.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:723"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4963.1700" negate="false" test_ref="oval:org.mitre.oval:tst:722"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:178" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5 Improper Cross Domain Security Validation with Dialog Box</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1326"/>
        <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3078"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3077"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3076"/>
          <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 5.50.4923.2500" negate="false" test_ref="oval:org.mitre.oval:tst:2849"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3013"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1779" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Denial of Service Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1184"/>
        <description>Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:30.657-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Msdtctm.dll is less than 2001.12.4720.480" negate="false" test_ref="oval:org.mitre.oval:tst:902"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1778" version="1" class="vulnerability">
      <metadata>
        <title>Win2K MDAC RDS.Dataspace Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>MDAC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
        <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="MDAC 2.5(SP3), 2.7(SP1), 2.8, or 2.8(SP1) is installed without patches for MS06-014">
          <criteria operator="AND" comment="MDAC 2.5,SP3 with msadco.dll version less than 2.53.6306.0">
            <criterion comment="MDAC 2.5 (SP3) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:729"/>
            <criterion comment="the version of msadco.dll is less than 2.53.6306.0" negate="false" test_ref="oval:org.mitre.oval:tst:728"/>
          </criteria>
          <criteria operator="AND" comment="MDAC 2.7,SP1 with msadco.dll version less than 2.71.9053.0">
            <criterion comment="MDAC 2.7 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2382"/>
            <criterion comment="the version of msadco.dll is less than 2.71.9053.0" negate="false" test_ref="oval:org.mitre.oval:tst:727"/>
          </criteria>
          <criteria operator="AND" comment="MDAC 2.8 with msadco.dll version less than 2.80.1062.0000">
            <criterion comment="MDAC 2.8 (RTM) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
            <criterion comment="the version of msadco.dll is less than 2.80.1062.0000" negate="false" test_ref="oval:org.mitre.oval:tst:726"/>
          </criteria>
          <criteria operator="AND" comment="MDAC 2.8,SP1 with msadco.dll version less than 2.81.1124.0">
            <criterion comment="MDAC 2.8 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:725"/>
            <criterion comment="the version of msadco.dll is less than 2.81.1124.0" negate="false" test_ref="oval:org.mitre.oval:tst:724"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1776" version="2" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.526-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:24.157-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.537" negate="false" test_ref="oval:org.mitre.oval:tst:730"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1775" version="2" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.316-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:23.671-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1774" version="1" class="vulnerability">
      <metadata>
        <title>IE5 HTA Execution Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1773" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Tag Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1188"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1771" version="2" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (S03-Gold, Itanium) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:54.489-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.504" negate="false" test_ref="oval:org.mitre.oval:tst:731"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:177" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 CDE ToolTalk Database Heap Corruption Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0679"/>
        <description>Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database server (rpc.ttdbserverd) allows remote attackers to execute arbitrary code via an argument to the _TT_CREATE_FILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 107893-20 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2850"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1769" version="2" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (64-bit XP) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:53.493-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false" test_ref="oval:org.mitre.oval:tst:732"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1768" version="2" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:30.178-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:23.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1767" version="2" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.982-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:22.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1766" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Multiple Event Handler Memory Corruption (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1765" version="2" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.820-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:22.243-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1764" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 COM object Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
        <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of shell32.dll is less than 6.0.3790.503" negate="false" test_ref="oval:org.mitre.oval:tst:733"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1763" version="2" class="vulnerability">
      <metadata>
        <title>RPC Mutual Authentication Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2380"/>
        <description>Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.673-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:21.799-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.7085" negate="false" test_ref="oval:org.mitre.oval:tst:734"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1762" version="1" class="vulnerability">
      <metadata>
        <title>WU-FTPD "glob-*" Remote DoS Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0256"/>
        <description>The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir copmmand.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="INETSVCS-RUN without patch PHNE_34544 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed">
          <criteria operator="AND" comment="INETSVCS-RUN without patch PHNE_34544 or later">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:981"/>
            <criterion comment="Patch PHNE_34544 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:736"/>
          </criteria>
          <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:735"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1761" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Access Requests Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0061"/>
        <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false" test_ref="oval:org.mitre.oval:tst:1025"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:176" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.514-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:21.329-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33395 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1756" version="2" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.328-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:20.829-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of jgdw400.dll is less than 106.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:835"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1754" version="1" class="vulnerability">
      <metadata>
        <title>"su" Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>LDAP</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00637553"/>
        <description>'An undisclosed vulnerability has been identified in su when used with LDAP.  The potential vulnerability could be exploited by a local authorized user to gain unauthorized access.'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_34545 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1752" version="2" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:29.199-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:20.420-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1751" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP/Server 2003 (64-Bit) VDM Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0208"/>
        <description>The Virtual DOS Machine (VDM) subsystem of Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 allows local users to access kernel memory and gain privileges via a malicious program that modified some system structures in a way that is not properly validated by privileged operating system functions.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:27:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-10-13T11:42:00.000-04:00" comment="fixed OS">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the patch KB840987 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2356"/>
        <criterion comment="the version of win32k.sys is less than 5.2.3790.198" negate="false" test_ref="oval:org.mitre.oval:tst:738"/>
        <criteria operator="OR" comment="Windows 2003 Server or Windows XP 64-bit">
          <criteria operator="AND" comment="Windows XP 64-bit">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1750" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2003 Remote Code Execution via Malformed Record</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031"/>
        <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:664 (referenced by tst:888) fixed; was pattern match, now equals.  Thanks to John Hoyland of Centennial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:887) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:36:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:28.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:888"/>
        <criterion comment="the version of excel.exe is less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:887"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:175" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE ToolTalk Database Server Symbolic Link Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0678" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0678"/>
        <description>CDE ToolTalk database server (ttdbserver) allows local users to overwrite arbitrary files via a symlink attack on the transaction log file used by the _TT_TRANSACTION RPC procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 110286-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3104"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1749" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Long Share Names Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0214"/>
        <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T01:33:00.000-04:00" comment="modified wft-517 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:50.652-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criteria operator="OR" comment="a vulnerable version of shell32.dll exists">
          <criteria operator="AND" comment="a vulnerable version of shell32.dll exists on NT Server">
            <criteria operator="OR" comment="Windows NT server product option">
              <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
              <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
            </criteria>
            <criteria operator="OR" comment="a vulnerable version of shell32.dll exists">
              <criteria operator="AND" comment="Active Desktop is installed and shell32.dll is less than 4.72.3843.3100">
                <criterion comment="Active Desktop  is installed" negate="false" test_ref="oval:org.mitre.oval:tst:743"/>
                <criterion comment="the version of shell32.dll is less than 4.72.3843.3100" negate="false" test_ref="oval:org.mitre.oval:tst:742"/>
              </criteria>
              <criteria operator="AND" comment="Active Desktop is not installed and shell32.dll is less than 4.0.1381.7267">
                <criterion comment="Active Desktop  is installed" negate="true" test_ref="oval:org.mitre.oval:tst:743"/>
                <criterion comment="the version of shell32.dll is less than 4.0.1381.7267" negate="false" test_ref="oval:org.mitre.oval:tst:741"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="a vulnerable version of shell32.dll exists on NT Terminal Server">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of shell32.dll is less than 4.0.1381.3356" negate="false" test_ref="oval:org.mitre.oval:tst:740"/>
          </criteria>
        </criteria>
        <criterion comment="the patch q841356 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:739"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1748" version="1" class="vulnerability">
      <metadata>
        <title>FPSE XSS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>FrontPage Server Extensions</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0015"/>
        <description>Cross-site scripting (XSS) vulnerability in _vti_bin/_vti_adm/fpadmdll.dll in Microsoft FrontPage Server Extensions 2002 and SharePoint Team Services allows remote attackers to inject arbitrary web script or HTML, then leverage the attack to execute arbitrary programs or create new accounts, via the (1) operation, (2) command, and (3) name parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-13T02:47:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-19T10:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-10T08:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="the version of fpadmdll.dll is less than 10.0.6790.0" negate="false" test_ref="oval:org.mitre.oval:tst:744"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1747" version="1" class="vulnerability">
      <metadata>
        <title>Webproxy Off-by-One Error in mod_ssl CRL</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1744" version="2" class="vulnerability">
      <metadata>
        <title>WinXP IP Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0048" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0048"/>
        <description>Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:50.430-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
        <criteria operator="OR" comment="A vulnerable version of tcpip.sys is installed.">
          <criteria operator="AND" comment="Service Pack 1 is installed and tcpip.sys is less than 5.1.2600.1693">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1693" negate="false" test_ref="oval:org.mitre.oval:tst:776"/>
          </criteria>
          <criteria operator="AND" comment="Service Pack 2 is installed and tcpip.sys is less than 5.1.2600.2685">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2685" negate="false" test_ref="oval:org.mitre.oval:tst:775"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1743" version="1" class="vulnerability">
      <metadata>
        <title>Windows (S03/64-bit XP) COM object Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
        <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP 64-bit or S03,SP1 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criteria operator="AND" comment="S03,SP1 is installed">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of shell32.dll is less than 6.0.3790.2662" negate="false" test_ref="oval:org.mitre.oval:tst:745"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1742" version="1" class="vulnerability">
      <metadata>
        <title>Windows (S03,SP1/XP 64-bit) MDAC RDS.Dataspace Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MDAC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
        <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP 64-bit or S03,SP1 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criteria operator="AND" comment="S03,SP1 is installed">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of msadco.dll is less than 2.82.2644.0" negate="false" test_ref="oval:org.mitre.oval:tst:746"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1741" version="2" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:28.842-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:20.005-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of rasmans.dll is less than 5.0.2195.7093" negate="false" test_ref="oval:org.mitre.oval:tst:747"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1740" version="1" class="vulnerability">
      <metadata>
        <title>IE5 Address Bar Spoofing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:174" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <description>An SCLT_INCOMPLETE error was blocking receipt of proper READY status from the array.  A timer was changed to allow array to reach full READY before SCSI response is tested.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:28.688-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:19.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.ARRAY-MGMT or OS-Core.ADMN-ENG-A-MAN (11.11)" negate="false">
          <criterion comment="OS-Core.ARRAY-MGMT (B.11.11) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4152"/>
          <criterion comment="OS-Core.ADMN-ENG-A-MAN (B.11.11) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3830"/>
        </criteria>
        <criterion comment="Patch PHCO_23263 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3210"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1738" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Word2002 Malformed Object Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2492"/>
        <description>Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:28.469-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:19.071-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.6802.0" negate="false" test_ref="oval:org.mitre.oval:tst:748"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1736" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3528.700" negate="false" test_ref="oval:org.mitre.oval:tst:749"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1735" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Script Execution Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1190"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1732" version="1" class="vulnerability">
      <metadata>
        <title>/usr/lib/print/conv_fix Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1360" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1360"/>
        <description>Unknown vulnerability in conv_fix in Sun Solaris 7 through 9, when invoked by conv_lpd, allows local users to overwrite arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="SunSoft Print - Client - Usr (SUNWpcu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:753"/>
        <criterion comment="Patch 107115-14 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:752"/>
        <criterion comment="Patch 109320-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:751"/>
        <criterion comment="Patch 113329-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:750"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1730" version="2" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:28.315-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:18.629-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:1132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:173" version="1" class="vulnerability">
      <metadata>
        <title>Apache prefork MPM Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0253" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0253"/>
        <description>The prefork MPM in Apache 2 before 2.0.47 does not properly handle certain errors from accept, which could lead to a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.5" negate="false" test_ref="oval:org.mitre.oval:tst:2852"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1729" version="2" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v10.0 on WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:28.164-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:18.177-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Windows Media Player 10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:833"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of wmp.dll is less than 10.0.0.4036" negate="false" test_ref="oval:org.mitre.oval:tst:754"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1728" version="2" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:27.984-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:17.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1727" version="1" class="vulnerability">
      <metadata>
        <title>Webproxy CGI Byterange Request DoS</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1725" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Address Bar Spoofing Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1724" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTA Execution Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1721" version="2" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (VS.NET 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Visual Studio .NET 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-24T04:32:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-29T02:08:00.000-04:00">DRAFT</status_change>
            <modified date="2004-09-30T11:39:00.000-04:00" comment="changed affected platforms">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-10-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check KB830348.  Added check for VS.NET Gdiplus.dll in WinSxS.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 578 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:27.749-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Visual Studio .NET 2003 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:756"/>
        <criterion comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" negate="false" test_ref="oval:org.mitre.oval:tst:755"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1720" version="2" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:27.624-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:17.355-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of rasmans.dll is less than 5.2.3790.529" negate="false" test_ref="oval:org.mitre.oval:tst:757"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1718" version="1" class="vulnerability">
      <metadata>
        <title>Windows Virtual DOS Machine Local Privilege Escalation Vulnerability (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0118"/>
        <description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="OR" comment="Version check of Ntoskrnl for NT Terminal Server or NT Workstation">
          <criteria operator="AND" comment="Version Ntoskrnl.exe is less than 4.0.1381.7265 and this is an NT Workstation">
            <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.7265" negate="false" test_ref="oval:org.mitre.oval:tst:759"/>
            <criterion comment="this is an NT Workstation" negate="false" test_ref="oval:org.mitre.oval:tst:2703"/>
          </criteria>
          <criteria operator="AND" comment="This is an NT Terminal Server and the version of Ntoskrnl.exe is less than 4.0.1381.33563">
            <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.33563" negate="false" test_ref="oval:org.mitre.oval:tst:758"/>
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1714" version="1" class="vulnerability">
      <metadata>
        <title>VirusVault Off-by-One Error in mod_ssl CRL</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1712" version="2" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:27.461-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:16.956-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.2709" negate="false" test_ref="oval:org.mitre.oval:tst:760"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1711" version="1" class="vulnerability">
      <metadata>
        <title>IE5 HTML Parsing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1185"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1710" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Cross-Domain Information Disclosure Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1191"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:171" version="2">
      <metadata>
        <title>Window Location Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-3640" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3640" source="CVE"/>
        <description>Microsoft Internet Explorer 5.01 and 6 allows certain script to persist across navigations between pages, which allows remote attackers to obtain the window location of visited web pages in other domains or zones, aka "Window Location Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:54.442-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.019-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.554" negate="false" test_ref="oval:org.mitre.oval:tst:136"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2759" negate="false" test_ref="oval:org.mitre.oval:tst:175"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2963" negate="false" test_ref="oval:org.mitre.oval:tst:95"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1561" negate="false" test_ref="oval:org.mitre.oval:tst:56"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3842.3000" negate="false" test_ref="oval:org.mitre.oval:tst:106"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1707" version="1" class="vulnerability">
      <metadata>
        <title>Enterprise Storage Manager 2.1 SAN Manager management station patch</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Sun Enterprise Storage Manager (ESM)</product>
        </affected>
        <description/>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Sun Enterprise Storage Manager installed" negate="false" test_ref="oval:org.mitre.oval:tst:762"/>
        <criterion comment="Patch 117367-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:761"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1704" version="1" class="vulnerability">
      <metadata>
        <title>IE6 COM Object Instantiation Memory Corruption (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1702" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Call Memory Corruption (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1701" version="1" class="vulnerability">
      <metadata>
        <title>IE AbusiveParent Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
        <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit with SP1 (or earlier) installed">
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criterion comment="the version of wdhtmled.ocx is less than 6.1.0.9232" negate="false" test_ref="oval:org.mitre.oval:tst:763"/>
        <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:170" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1228" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1228"/>
        <description>Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:27.272-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:16.282-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112668-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4005"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 112669-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:4070"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116340-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3666"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 116341-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3778"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120719-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3295"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101816 criteria." negate="false">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 120720-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3621"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:17" version="1" class="vulnerability">
      <metadata>
        <title>IE GetObject Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0023"/>
        <description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="changed IE test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2713.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3091"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1698" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Privilege Escalation Using crypto.generateCRMFRequest</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1728"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:27.013-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1697" version="1" class="vulnerability">
      <metadata>
        <title>X.Org Privilege Escalation Vulnerability in X11R6.9, X11R7.0</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0745" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0745"/>
        <description>X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite arbitrary files via -logfile.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-21T04:03:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
        <criteria operator="AND" comment="Patch 118966-14 through 118966-16 is installed.">
          <criterion comment="Patch 118966-14 or later installed" negate="false" test_ref="oval:org.mitre.oval:tst:765"/>
          <criterion comment="Patch 118966-17 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:764"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1696" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Insecure Default ACLs</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0023"/>
        <description>Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 582 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:26.765-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Patch WinXP-KB914798 is installed." negate="true" test_ref="oval:org.mitre.oval:tst:766"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1695" version="1" class="vulnerability">
      <metadata>
        <title>DHTML Object Memory Corruption Vulnerability (IE6 for XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0553" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0553"/>
        <description>Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2627" negate="false" test_ref="oval:org.mitre.oval:tst:768"/>
          <criterion comment="the patch kb890923  is installed (XP SP2 Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:767"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1690" version="1" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550"/>
        <description>An undisclosed vulnerability has been identified in /sbin/passwd which could be exploited to create a Denial of Service condition..</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX2-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:771"/>
        <criterion comment="Patch PHCO_32149 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:770"/>
        <criterion comment="Patch PHCO_32926 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:769"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:169" version="1" class="vulnerability">
      <metadata>
        <title>Apache Weak Cipher Suite Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0192"/>
        <description>Apache 2 before 2.0.47, and certain versions of mod_ssl for Apache 1.3, do not properly handle "certain sequences of per-directory renegotiations and the SSLCipherSuite directive being used to upgrade from a weak ciphersuite to a strong one," which could cause Apache to use the weak ciphersuite.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-05T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.5" negate="false" test_ref="oval:org.mitre.oval:tst:2852"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd.worker is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2851"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1689" version="1" class="vulnerability">
      <metadata>
        <title>Sendmail setjmp longjmp bo (Red Hat Internal)</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <platform>Red Hat Enterprise Linux 3</platform>
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>Sendmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0058"/>
        <description>Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in a way that causes the setjmp and longjmp function calls to be interrupted and modify unexpected memory locations.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-27T09:51:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="sendmail before 8.12.x is installed" negate="false" test_ref="oval:org.mitre.oval:tst:774"/>
        <criterion comment="sendmail 8.12.x before 8.12.11 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:773"/>
        <criterion comment="sendmail 8.13.x before 8.13.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:772"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1688" version="1" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in Server 2003,SP1</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Imekr61.ime is less than 6.2.2551.0 (64-bit)" negate="false" test_ref="oval:org.mitre.oval:tst:834"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1687" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (moz-grid)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1738" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1738"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:26.582-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1686" version="2" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:26.440-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:15.778-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1685" version="2" class="vulnerability">
      <metadata>
        <title>WinXP Land Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0688"/>
        <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:50.188-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
        <criteria operator="OR" comment="A vulnerable version of tcpip.sys is installed.">
          <criteria operator="AND" comment="Service Pack 1 is installed and tcpip.sys is less than 5.1.2600.1693">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1693" negate="false" test_ref="oval:org.mitre.oval:tst:776"/>
          </criteria>
          <criteria operator="AND" comment="Service Pack 2 is installed and tcpip.sys is less than 5.1.2600.2685">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2685" negate="false" test_ref="oval:org.mitre.oval:tst:775"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1684" version="1" class="vulnerability">
      <metadata>
        <title>sendfilev DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>sendfilev()</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1356" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1356"/>
        <description>Unknown vulnerability in the sendfilev function in Sun Solaris 8 and 9 allows local users to cause a denial of service (system panic) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Patch 108528-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:778"/>
        <criterion comment="Patch 112233-12 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:777"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1682" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express 6,SP1 WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP,SP1 32-bit or Win2K,SP4 is installed">
          <criteria operator="AND" comment="Windows XP,SP1 32-bit is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
        </criteria>
        <criterion comment="Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.2800.1807" negate="false" test_ref="oval:org.mitre.oval:tst:779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1679" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 COM object Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
        <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of shell32.dll is less than 6.0.2800.1816" negate="false" test_ref="oval:org.mitre.oval:tst:780"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1678" version="1" class="vulnerability">
      <metadata>
        <title>IE 5.01 DHTML Method Call Memory Corruption</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1677" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Parsing Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1185" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1185"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1676" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTA Execution Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1674" version="2" class="vulnerability">
      <metadata>
        <title>RASMAN Registry Corruption Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2371" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2371"/>
        <description>Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:26.309-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:15.353-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of rasmans.dll is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:836"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1671" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Insecure Default ACLs</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0023" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0023"/>
        <description>Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka "Permissive Windows Services DACLs."  NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 589 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:26.136-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Patch S03-KB914798 is installed." negate="true" test_ref="oval:org.mitre.oval:tst:781"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:167" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express 6,2003 News Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1213"/>
        <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 6 for Windows 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2855"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.326" negate="false" test_ref="oval:org.mitre.oval:tst:2854"/>
        <criterion comment="Patch KB897715 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1668" version="2" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:26.003-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:14.901-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Wjgdw400.dll is less than 106.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:782"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1667" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CSS BO)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1739" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1739"/>
        <description>The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:25.785-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1666" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2002 Remote Code Execution via Malformed Graphic</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2377) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:1360 (referenced by tst:2378) fixed: was pattern match, now equals.  Thanks to John Hoyland of Centenial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:25.574-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2378"/>
        <criterion comment="the version of excel.exe is less than 10.0.6789.0" negate="false" test_ref="oval:org.mitre.oval:tst:2377"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1665" version="2" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:25.404-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:14.406-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1664" version="1" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in Windows XP</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Imekr61.ime is less than 6.1.2600.3 (WinXP)" negate="false" test_ref="oval:org.mitre.oval:tst:783"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1662" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP IGMP v3 Denial of Service (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0021"/>
        <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1792 (XP,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:784"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1661" version="1" class="vulnerability">
      <metadata>
        <title>Windows Media Player 9 Bitmap Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
        <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:786"/>
        <criterion comment="the version of Wmp.dll is less than 9.0.0.3344" negate="false" test_ref="oval:org.mitre.oval:tst:785"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1660" version="1" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550"/>
        <description>An undisclosed vulnerability has been identified in /sbin/passwd which could be exploited to create a Denial of Service condition..</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:961"/>
        <criterion comment="Patch PHCO_33214 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:788"/>
        <criterion comment="Patch PHCO_33215 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1659" version="1" class="vulnerability">
      <metadata>
        <title>VirusVault Integer Overflow in pcre_compile</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1657" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Call Memory Corruption (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1656" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Access Requests Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0061" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0061"/>
        <description>The kernel of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via certain access requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" negate="false" test_ref="oval:org.mitre.oval:tst:2738"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1655" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Font Conversion Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Replaced all criteria. 1) Included all S03 versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of wordpad.exe is less than 5.2.3790.224" negate="false" test_ref="oval:org.mitre.oval:tst:2570"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1654" version="1" class="vulnerability">
      <metadata>
        <title>gzip -force File Permission Alteration Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Licence Logging Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1349" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1349"/>
        <description>gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T12:13:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T05:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        <criterion comment="GNU Zip (gzip, SUNWgzip) installed" negate="false" test_ref="oval:org.mitre.oval:tst:790"/>
        <criterion comment="Patch 112668-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:789"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1653" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Routing Slip</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009"/>
        <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1651" version="1" class="vulnerability">
      <metadata>
        <title>IE6 COM Object Instantiation Memory Corruption (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1650" version="1" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in Server 2003</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Imekr61.ime is less than 6.1.3790.1 (S03-Gold)" negate="false" test_ref="oval:org.mitre.oval:tst:791"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1649" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Privilege Escalation through Print Preview</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1727" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1727"/>
        <description>Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to gain chrome privileges via multiple attack vectors related to the use of XBL scripts with "Print Preview".</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:25.160-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1647" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP IGMP v3 Denial of Service (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0021"/>
        <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2431"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1646" version="2" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:25.007-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:13.900-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1645" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Address Bar Spoofing Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1644" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft JScript Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:24.831-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:13.461-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Jscript.dll is less than 5.1.0.12512" negate="false" test_ref="oval:org.mitre.oval:tst:792"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1642" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTA Execution Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1640" version="2" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:24.634-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:13.021-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of jgdw400.dll is less than 106.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:835"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:164" version="1" class="vulnerability">
      <metadata>
        <title>Trustix Secure Linux der_chop Script Symlink Attack Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0975" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0975"/>
        <description>The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-14T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-15T09:48:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criteria operator="OR" comment="openssl, openssl-devel, OR openssl-perl older than 0.9.7a-33.15 or openssl096b older than 0.9.6b-16.22.3">
            <criterion comment="openssl-perl is older than 0.9.7a-33.15" negate="false" test_ref="oval:org.mitre.oval:tst:2860"/>
            <criterion comment="openssl-devel older than 0.9.7a-33.15" negate="false" test_ref="oval:org.mitre.oval:tst:2859"/>
            <criterion comment="openssl older than 0.9.7a-33.15" negate="false" test_ref="oval:org.mitre.oval:tst:2858"/>
            <criterion comment="openssl096b package is older than 0.9.6b-16.22.3.i386.rpm" negate="false" test_ref="oval:org.mitre.oval:tst:2857"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/tmp is writable by everyone" negate="false" test_ref="oval:org.mitre.oval:tst:2856"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1638" version="1" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in IE5.01</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0020"/>
        <description>An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a crafted WMF file with a manipulated WMF header size, possibly involving an integer overflow, a different vulnerability than CVE-2005-4560, and aka "WMF Image Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3837.1200" negate="false" test_ref="oval:org.mitre.oval:tst:793"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1637" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1124"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1636" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.22)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.22">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN (B.11.22) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:795"/>
        <criterion comment="Patch PHNE_29462 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:794"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1635" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed File Format</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1633" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2000 Remote Code Execution via Malformed Description</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:1110) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:24.451-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8938" negate="false" test_ref="oval:org.mitre.oval:tst:1110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1632" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Multiple Event Handler Memory Corruption (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1630" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Graphic</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:707" version="2">
      <metadata>
        <title>Microsoft Project 2002, SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Project 2002, SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.895-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.024-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Project 2002, SP1 is installed" test_ref="oval:org.mitre.oval:tst:555"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:663" version="2">
      <metadata>
        <title>Microsoft Office 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Office 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.244-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.628-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office 2002 is installed" test_ref="oval:org.mitre.oval:tst:2327"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:475" version="2">
      <metadata>
        <title>Microsoft Word 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Word 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:29:28.006-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:41.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:163" version="2">
      <metadata>
        <title>Microsoft Office Remote Code Execution Using a Malformed PNG Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0033" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-27T12:28:50.595-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:23.128-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="vulnerable applications" operator="OR">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
          <extend_definition comment="Microsoft Project 2002, SP1 is installed" definition_ref="oval:org.mitre.oval:def:707"/>
          <extend_definition comment="Microsoft Office 2002 is installed" definition_ref="oval:org.mitre.oval:def:663"/>
        </criteria>
        <criterion comment="the version of Png32.flt is less than 2003.1100.8029.0" test_ref="oval:org.mitre.oval:tst:7"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1629" version="1" class="vulnerability">
      <metadata>
        <title>Webproxy HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1628" version="1" class="vulnerability">
      <metadata>
        <title>CD Drive DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0901"/>
        <description>Unspecified vulnerability in the hsfs filesystem in Solaris 8, 9, and 10 allows unspecified attackers to cause a denial of service (panic) or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-26T12:31:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109764-06 or later installed (SPARC-8)" negate="true" test_ref="oval:org.mitre.oval:tst:801"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116047-03 or later installed (SPARC-9)" negate="true" test_ref="oval:org.mitre.oval:tst:800"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 119596-03 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:799"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109765-06 or later installed (x86-8)" negate="true" test_ref="oval:org.mitre.oval:tst:798"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121995-01 or later installed (x86-9)" negate="true" test_ref="oval:org.mitre.oval:tst:797"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102161 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118813-03 or later installed (x86-10)" negate="true" test_ref="oval:org.mitre.oval:tst:796"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1625" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla "AnyName" Entrainment and Access Control Hazard</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0299" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0299"/>
        <description>The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1621" version="2" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:24.300-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:12.496-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1555" negate="false" test_ref="oval:org.mitre.oval:tst:802"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1619" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Firefox History File Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4134" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4134"/>
        <description>Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup.  NOTE: despite initial reports, the Mozilla vendor does not believe that this issue can be used to trigger a crash or buffer overflow in Firefox.  Also, it has been independently reported that Netscape 8.1 does not have this issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-26T01:41:00.000-04:00" comment="Updated reference to CVE-2005-4134">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-02-01T05:57:00.000-04:00" comment="Changed affected products to Firefox, Mozilla.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-02-07T06:26:00.000-04:00" comment="Updated criteria to reflect Mozilla Security Advisories dated February 1, 2006">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox pre-1.5 is installed">
          <criterion comment="Mozilla Firefox pre-1.5" negate="false" test_ref="oval:org.mitre.oval:tst:2445"/>
          <criterion comment="Firefox pre-1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2444"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite is installed">
          <criterion comment="Mozilla Suite installed" negate="false" test_ref="oval:org.mitre.oval:tst:2441"/>
          <criterion comment="Mozilla Suite is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2440"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1618" version="1" class="vulnerability">
      <metadata>
        <title>pagedata Subsystem Local DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://sunsolve9.sun.com/search/document.do?assetkey=1-26-102159-1&amp;amp;searchclause="/>
        <description>'An undisclosed vulnerability in the pagedata subsystem in /proc may allow a local unprivileged user to cause significant performance degradation and even panic the system.'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-04T10:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102159 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 117350-33 or later installed (SPARC-8)" negate="true" test_ref="oval:org.mitre.oval:tst:808"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102159 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118558-22 or later installed (SPARC-9)" negate="true" test_ref="oval:org.mitre.oval:tst:807"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102159 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118822-29 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:806"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102159 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 117351-33 or later installed (x86-8)" negate="true" test_ref="oval:org.mitre.oval:tst:805"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102159 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118559-22 or later installed (x86-9)" negate="true" test_ref="oval:org.mitre.oval:tst:804"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102159 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118844-29 or later installed (x86-10)" negate="true" test_ref="oval:org.mitre.oval:tst:803"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1617" version="1" class="vulnerability">
      <metadata>
        <title>XPM Image Decoder Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0782" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0782"/>
        <description>Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow.  NOTE: this identifier is ONLY for gtk+.  It was incorrectly referenced in an advisory for a different issue (CVE-2004-0687).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-21T04:03:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114644-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:817"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 8 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114645-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:816"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114686-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:815"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (SPARC) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115738-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:813"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:818"/>
          <criterion comment="Patch 114687-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:812"/>
        </criteria>
        <criteria operator="AND" comment="GNOME 2.0.2 Solaris 9 (x86) meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Gnome 2.0.2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:814"/>
          <criterion comment="Patch 115739-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:811"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) with JDS release 2 meets Sun Alert ID 101776 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="JDS release 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:810"/>
          <criterion comment="Patch 121092-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:809"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1614" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla CSS Letter-Spacing Heap Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1730" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1730"/>
        <description>Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:24.010-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1612" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.462" negate="false" test_ref="oval:org.mitre.oval:tst:819"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1611" version="2" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (XP,SP2) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:52.680-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.2900.2869" negate="false" test_ref="oval:org.mitre.oval:tst:820"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:161" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT SNMPv1 Trap Handling DoS and Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012"/>
        <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of snmp.exe is less than 4.0.1381.7134" negate="false" test_ref="oval:org.mitre.oval:tst:2960"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1609" version="2" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (WinXP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:23.849-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:12.019-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2912" negate="false" test_ref="oval:org.mitre.oval:tst:821"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1608" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 10 find on /proc panic DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0191"/>
        <description>Unspecified vulnerability in Sun Solaris 10 allows local users to cause a denial of service (null dereference) via unspecified vectors involving the use of the find command on the "/proc" filesystem. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2005-3250.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-12T11:25:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (sparc) meets Sun Alert ID 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118822-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:822"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102066 and 102108 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118844-24 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2409"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1607" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion comment="Patch PHNE_33159 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:823"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1606" version="1" class="vulnerability">
      <metadata>
        <title>SMB Code Execution Vulnerability (32-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0045"/>
        <description>The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T10:39:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mrxsmb.sys is less than 5.1.2600.2598" negate="false" test_ref="oval:org.mitre.oval:tst:825"/>
        <criterion comment="the patch KB885250 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:824"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1604" version="2" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:23.690-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:11.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1603" version="1" class="vulnerability">
      <metadata>
        <title>HyperTerminal Session File Vulnerability (Windows XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>HyperTerminal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0568" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0568"/>
        <description>HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-01-18T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-01-27T12:00:00.000-04:00" comment="Change OS test to include XP gold in addition to XP SP1">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-03-02T12:00:00.000-04:00" comment="modified wft-175 - Access DLL via HKLM">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-03-23T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-03-29T12:00:00.000-04:00" comment="modified wrt-45 - deleted an extra space after Filelist">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-04-22T12:00:00.000-04:00" comment="modified wrt-45 - Removed extra space between 'Windows XP' in the key field">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </modified>
            <status_change date="2005-05-11T05:41:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of hypertrm.dll is less than 5.1.2600.1609" negate="false" test_ref="oval:org.mitre.oval:tst:829"/>
          <criterion comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed" negate="false" test_ref="oval:org.mitre.oval:tst:828"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="If key present hyperterminal will automatically open session files" negate="false" test_ref="oval:org.mitre.oval:tst:827"/>
          <criterion comment="If the Hyperterminal client is registered as the default telnet client" negate="false" test_ref="oval:org.mitre.oval:tst:826"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1602" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of webclnt.dll is less than 5.1.2600.2821 (XP,SP2)" negate="false" test_ref="oval:org.mitre.oval:tst:830"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1601" version="1" class="vulnerability">
      <metadata>
        <title>Windows ME Long Share Names Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0214"/>
        <description>Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names, as demonstrated using Samba.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:37:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows ME Installed" negate="false" test_ref="oval:org.mitre.oval:tst:831"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1600" version="2" class="vulnerability">
      <metadata>
        <title>Flash Address Bar Spoofing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1626" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1626"/>
        <description>Internet Explorer 6 for Windows XP SP2 and earlier allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash application is still loading.  NOTE: this is a different vulnerability than CVE-2006-1192.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:23.536-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:11.006-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:160" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Plug and Play Buffer Overflow Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:40:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:23.350-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:10.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:4033"/>
        <criterion comment="SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3342"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.2.3790.2477" negate="false" test_ref="oval:org.mitre.oval:tst:3535"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:16" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Chunked Encoding Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0079"/>
        <description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1599" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Multiple Event Handler Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:1598" version="3">
      <metadata>
        <title>Windows Media Player 10 Bitmap Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference ref_id="CVE-2006-0006" source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
        <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-05-31T01:08:00.000-04:00" comment="modified wrt-646 - Removed extra backslash from value regexp.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-05-31T09:44:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-22T07:56:12" comment="Restrict to XP and changed Wmp.dll version number per Apr11 changes to MS06-005.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:23.076-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Windows Media Player 10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:833"/>
        <criterion comment="the version of Wmp.dll is less than 10.0.0.4019" negate="false" test_ref="oval:org.mitre.oval:tst:832"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1597" version="1" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1595" version="1" class="vulnerability">
      <metadata>
        <title>Korean IME Privilege Elevation Vulnerability in 64-bit Windows XP</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0008"/>
        <description>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Imekr61.ime is less than 6.2.2551.0 (64-bit)" negate="false" test_ref="oval:org.mitre.oval:tst:834"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1591" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTA Execution Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1388" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1388"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1590" version="2" class="vulnerability">
      <metadata>
        <title>ART Image Rendering Vulnerability (2K/XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2378"/>
        <description>Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:22.899-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:09.888-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of jgdw400.dll is less than 106.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:835"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:159" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Trusted Domain Loophole</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows NT 4.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0018"/>
        <description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of netlogon.dll is less than 4.0.1381.7092" negate="false" test_ref="oval:org.mitre.oval:tst:2862"/>
        <criterion comment="Windows NT 4.0 Security Roll-up Package" negate="true" test_ref="oval:org.mitre.oval:tst:3036"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1589" version="1" class="vulnerability">
      <metadata>
        <title>IE6 COM Object Instantiation Memory Corruption (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1587" version="2" class="vulnerability">
      <metadata>
        <title>RRAS Memory Corruption Vulnerability (64-bit XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2370" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2370"/>
        <description>Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:22.746-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:09.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of rasmans.dll is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:836"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1586" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Shared Library Privilege Escalation Vulnerability (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0436"/>
        <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN, InternetSrvcs.INET-ENG-A-MAN, or VirtualVaultOS.VVOS-AUX-IA (B.11.04) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1279"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1278"/>
          <criterion comment="VirtualVaultOS.VVOS-AUX-IA is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1277"/>
        </criteria>
        <criterion comment="Patch PHCO_32280 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1585" version="2" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:22.550-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:08.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2892" negate="false" test_ref="oval:org.mitre.oval:tst:838"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1582" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX SIM Hangs MS-IE Due to MS04-025 Changes</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3983"/>
        <description>Unknown vulnerability in the login page for HP Systems Insight Manager (SIM) 4.0 and 4.1, when accessed by Microsoft Internet Explorer with the MS04-025 patch, leads to a denial of service (browser hang). NOTE: although the advisory is vague, this issue does not appear to involve an attacker at all.  If not, then this issue is not a vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="SysMgmtServer.MX-PORTAL (C.04.00.00.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:841"/>
        <criterion comment="SysMgmtServer.MX-PORTAL (C.04.01.00.00) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:840"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1581" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed Test OVAL1581 (Identical to OVAL4458)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T09:32:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of lsasrv.dll is less than 5.2.3790.220" negate="false" test_ref="oval:org.mitre.oval:tst:842"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
        <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1580" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos Command Execution Vulnerability rexec Daemon</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0769" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0769"/>
        <description>Unspecified vulnerability in in.rexecd in Solaris 10 allows local users to gain privileges on Kerberos systems via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-19T05:38:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102186 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
            <criterion comment="Patch 120329-02 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:845"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102186 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 120330-02 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:844"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Target is configured to reference pam_krb5" negate="false" test_ref="oval:org.mitre.oval:tst:843"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:158" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Process Handle Duplication Privilege Escalation</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows NT 4.0</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0367" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0367"/>
        <description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-04-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of smss.exe is less than 4.0.1381.7152" negate="false" test_ref="oval:org.mitre.oval:tst:2863"/>
        <criterion comment="Patch Q320206 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2972"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1579" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2003 Remote Code Execution via Malformed Description</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:664 (referenced by tst:888) fixed; was pattern match, now equals.  Thanks to John Hoyland of Centennial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:887) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:36:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:22.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:888"/>
        <criterion comment="the version of excel.exe is less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:887"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1578" version="1" class="vulnerability">
      <metadata>
        <title>Windows Media Player 7.10 Bitmap Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
        <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 7.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1066"/>
        <criterion comment="the version of Wmpui.dll is less than 7.10.0.3077" negate="false" test_ref="oval:org.mitre.oval:tst:846"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1577" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Shared Library Privilege Escalation Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0436"/>
        <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_29249 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:847"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1576" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd Remote Unauthorized Access (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>remshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS2-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.23) is installed">
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:849"/>
        </criteria>
        <criterion comment="Patch PHNE_33792 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:848"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1574" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (CVE-2006-1723)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1723" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1723"/>
        <description>Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML.  NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530, CVE-2006-1531, and CVE-2006-1723 are different.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:22.161-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird 1.5 is installed without an upgraded Firefox (1.5.0.2)">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1572" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX envd Local Execution of Privileged Code (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>envd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3564"/>
        <description>envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.11) is installed">
          <criterion comment="OS-Core.CORE-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:852"/>
          <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:851"/>
        </criteria>
        <criterion comment="Patch PHCO_33967 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:850"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1570" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Description</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1569" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Multiple Event Handler Memory Corruption (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1568" version="2" class="vulnerability">
      <metadata>
        <title>Server 2003 Media Player PNG Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1244"/>
        <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-23T08:48:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified objects 733, 734, 735, 736, 738, and 739 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:47.969-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Media Player 9.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:1004"/>
          <criterion comment="the version of wmp.dll is les than 9.0.0.3250" negate="false" test_ref="oval:org.mitre.oval:tst:1003"/>
          <criterion comment="The patch KB885492 is installed on Windows Server 2003" negate="true" test_ref="oval:org.mitre.oval:tst:853"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST">
            <criterion comment=".asx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:1001"/>
            <criterion comment=".wax EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:1000"/>
            <criterion comment=".wvx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:999"/>
            <criterion comment=".wpl EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:998"/>
            <criterion comment=".wmx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:997"/>
            <criterion comment=".wms EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:996"/>
            <criterion comment=".wmz EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:995"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1567" version="2" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:21.998-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:08.495-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1566" version="1" class="vulnerability">
      <metadata>
        <title>Leaking GSSAPI Credentials Vulnerability (B.11.00/B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2798"/>
        <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:869"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1564" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Gdi32.dll is less than 5.1.2600.1789" negate="false" test_ref="oval:org.mitre.oval:tst:854"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1563" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0,SP1 Drag-and-Drop Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0839" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0839"/>
        <description>Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-25T04:59:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-10-27T01:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-27T10:50:00.000-04:00" comment="modified wft-564 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1476" negate="false" test_ref="oval:org.mitre.oval:tst:856"/>
          <criterion comment="the patch kb834707 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:855"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1562" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla QueryInterface Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0295"/>
        <description>Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1561" version="1" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" negate="false" test_ref="oval:org.mitre.oval:tst:857"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:156" version="1" class="vulnerability">
      <metadata>
        <title>Apache Linefeed Allocation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0132" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0132"/>
        <description>A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via large chunks of linefeed characters, which causes Apache to allocate 80 bytes for each linefeed.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.1" negate="false" test_ref="oval:org.mitre.oval:tst:2866"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1559" version="1" class="vulnerability">
      <metadata>
        <title>Windows Media Player Plug-in EMBED Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0005" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0005"/>
        <description>Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EMBED element containing a long src attribute.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Npdsplay.dll is less than 3.0.2.629" negate="false" test_ref="oval:org.mitre.oval:tst:858"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1558" version="1" class="vulnerability">
      <metadata>
        <title>Win2K,SP4 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1557" version="2" class="vulnerability">
      <metadata>
        <title>Remote Code Execution Vulnerability in Flash Player 6&amp;7 (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Flash Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2628" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2628"/>
        <description>Macromedia Flash 6 and 7 (Flash.ocx) allows remote attackers to execute arbitrary code via a SWF file with a modified frame type identifier that is used as an out-of-bounds array index to a function pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:21.837-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Flash.ocx is less than 7.0.19.0" negate="false" test_ref="oval:org.mitre.oval:tst:859"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1556" version="2" class="vulnerability">
      <metadata>
        <title>CSS Cross-Domain Information Disclosure Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4089" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4089"/>
        <description>Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @import directive to download files from other domains that are not valid Cascading Style Sheets (CSS) files, as demonstrated using Google Desktop, aka "CSSXSS" and "CSS Cross-Domain Information Disclosure Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:21.719-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:07.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1555" version="2" class="vulnerability">
      <metadata>
        <title>Powerpoint TIFF Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>PowerPoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0004" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0004"/>
        <description>Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 649 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:21.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="PowerPoint 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:861"/>
        <criterion comment="the version of PowerPnt.exe is less than 9.0.0.8936" negate="false" test_ref="oval:org.mitre.oval:tst:860"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:93" version="2">
      <metadata>
        <title>Microsoft Office 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Office 2000 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:44">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:54.553-04:00">INTERIM</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Changed operation from pattern match to equals in obj:650.  Modified by Harvey Rubinovitz">
              <contributor organization="Secure Elements, Inc.">Glenn Strickland</contributor>
            </modified>
            <status_change date="2006-11-14T08:58:00.810-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office 2000 is installed" test_ref="oval:org.mitre.oval:tst:863"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:1553" version="3">
      <metadata>
        <title>Office 2000 Remote Code Execution via Malformed Routing Slip</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference ref_id="CVE-2006-0009" source="CVE" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009"/>
        <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-25T12:05:44" comment="changed tst:863 to only look for the existing object and applied an inventory definition.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:21.300-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <extend_definition comment="Microsoft Office 2000 is installed" definition_ref="oval:org.mitre.oval:def:93"/>
        <criterion comment="the version of Winword.exe is less than 9.0.0.8938" negate="false" test_ref="oval:org.mitre.oval:tst:862"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1552" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.22)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.22">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1442"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1551" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="shell32.dll is less than 6.0.3790.2534" negate="false" test_ref="oval:org.mitre.oval:tst:864"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1550" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:959"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:958"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:155" version="2">
      <metadata>
        <title>User Profile Elevation of Privilege Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3443" source="CVE"/>
        <description>Untrusted search path vulnerability in Winlogon in Microsoft Windows 2000 SP4, when SafeDllSearchMode is disabled, allows local users to gain privileges via a malicious DLL in the UserProfile directory, aka "User Profile Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:46.723-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:22.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Kernel32.dll is less than 5.0.2195.7099" test_ref="oval:org.mitre.oval:tst:80"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Kernel32.dll is less than 5.1.2600.1869" test_ref="oval:org.mitre.oval:tst:31"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Kernel32.dll is less than 5.1.2600.2945" test_ref="oval:org.mitre.oval:tst:45"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.2741" test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.556" test_ref="oval:org.mitre.oval:tst:63"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Kernel32.dll is less than 5.2.3790.2741" test_ref="oval:org.mitre.oval:tst:104"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1549" version="1" class="vulnerability">
      <metadata>
        <title>WINS Association Context Vulnerability (64-bit Server 2003, Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows Internet Naming Service (WINS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1080" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1080"/>
        <description>The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remote attackers to write to arbitrary memory locations and possibly execute arbitrary code via a modified memory pointer in a WINS replication packet to TCP port 42, aka the "Association Context Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Microsoft Windows Server 2003 64-Bit Edition">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          </criteria>
          <criterion comment="the version of wins.exe is less than 5.2.3790.239" negate="false" test_ref="oval:org.mitre.oval:tst:866"/>
          <criterion comment="the patch KB870763 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:865"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the wins service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2405"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1548" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Downloading Executables with "Save Image As..."</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1736" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1736"/>
        <description>Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to trick users into downloading and saving an executable file via an image that is overlaid by a transparent image link that points to the executable, which causes the executable to be saved when the user clicks the "Save image as..." option.  NOTE: this attack is made easier due to a GUI truncation issue that prevents the user from seeing the malicious extension when there is extra whitespace in the filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:21.133-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1547" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.453 (S03-Gold)" negate="false" test_ref="oval:org.mitre.oval:tst:867"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1546" version="1" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (32-bit Windows XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="version of Gdi32.dll is less than 5.1.2600.1755 OR the version of Mf3216.dll is less than 5.1.2600.1331">
          <criterion comment="the version of Gdi32.dll is less than 5.1.2600.1755" negate="false" test_ref="oval:org.mitre.oval:tst:1116"/>
          <criterion comment="the version of Mf3216.dll is less than 5.1.2600.1331" negate="false" test_ref="oval:org.mitre.oval:tst:1115"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1544" version="1" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="nwwks.dll is less than 5.2.3790.386" negate="false" test_ref="oval:org.mitre.oval:tst:868"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1543" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1542" version="1" class="vulnerability">
      <metadata>
        <title>zlib Compression Remote DoS Vulnerability (B.11.00/B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2096"/>
        <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:869"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1541" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Script Execution Vulnerability (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1190" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1190"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1538" version="1" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="a vulnerable version of mshtml.dll exists GDR/QFE">
          <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1522" negate="false" test_ref="oval:org.mitre.oval:tst:871"/>
          <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1523" negate="false" test_ref="oval:org.mitre.oval:tst:870"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1537" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="shell32.dll is less than 6.0.3790.413" negate="false" test_ref="oval:org.mitre.oval:tst:872"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1536" version="2" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="nwwks.dll is less than 5.0.2195.7065" negate="false" test_ref="oval:org.mitre.oval:tst:873"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1535" version="2" class="vulnerability">
      <metadata>
        <title>Win2k,SP4 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.767-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="mshtml.dll is less than 5.0.3833.200" negate="false" test_ref="oval:org.mitre.oval:tst:874"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1534" version="1" class="vulnerability">
      <metadata>
        <title>uucp/uustat Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0161" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0161"/>
        <description>Unspecified vulnerability in uucp in Sun Solaris 8 and 9 has unknown impact and attack vectors.  NOTE: due to the vagueness of the vendor advisory, it is not clear whether this is related to CVE-2004-0780.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-17T01:07:00.000-04:00" comment="Updated reference to CVE-2006-0161, per Rob Hollis.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 111570-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:878"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 111571-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:877"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113322-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:876"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101933 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 115880-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:875"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1533" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.11-IPSEC)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="IPSec.IPSEC2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:966"/>
        <criteria operator="OR" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0">
          <criterion comment="IPSec.IPSEC2-KRN with version less than A.2.00.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:965"/>
          <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:964"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1532" version="1" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Windows XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="netman.dll is less than 5.1.2600.2743" negate="false" test_ref="oval:org.mitre.oval:tst:879"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1530" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP HtmlHelp Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0201"/>
        <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="added the unregistered HTML Help criterion to the configuration section of the criteria">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:37:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1528" version="1" class="vulnerability">
      <metadata>
        <title>ls-F Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>TENEX C Shell (tcsh)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1024" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1024"/>
        <description>Unknown vulnerability in the ls-F builtin function in tcsh on Solaris 8 allows local users to create or delete files as other users, and gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-08-22T04:00:00.000-04:00" comment="Affected product changed to tcsh; mistakenly was .NET framework">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
        <criterion comment="Patch 110943-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:880"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1526" version="1" class="vulnerability">
      <metadata>
        <title>VirusVault HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1525" version="1" class="vulnerability">
      <metadata>
        <title>Excel Viewer 2003 Remote Code Execution via Malformed Record</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031"/>
        <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Xlview.exe is installed with a version less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1523" version="1" class="vulnerability">
      <metadata>
        <title>Unsupported Version of Windows</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://www.microsoft.com/sp"/>
        <description>'As Service Packs released by Microsft mature, earlier versions and releases become unspported.  This equates to a cessation in software and security patches for that baseline.  Using an unsupported version of Windows represents a severe security risk.'</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="An unsupported version of Windows XP is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        </criteria>
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1522" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2002 Remote Code Execution via Malformed Description</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0029" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0029"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2377) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:1360 (referenced by tst:2378) fixed: was pattern match, now equals.  Thanks to John Hoyland of Centenial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.570-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2378"/>
        <criterion comment="the version of excel.exe is less than 10.0.6789.0" negate="false" test_ref="oval:org.mitre.oval:tst:2377"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1521" version="1" class="vulnerability">
      <metadata>
        <title>Win2K,SP4 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1520" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 (64-bit) COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:152" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 X Font Server Remote Buffer Overrun</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>fs.auto, xfs</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1317"/>
        <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File fs.auto exists" negate="false" test_ref="oval:org.mitre.oval:tst:2873"/>
          <criterion comment="File xfs exists" negate="false" test_ref="oval:org.mitre.oval:tst:2872"/>
          <criterion comment="Patch 108117-06 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2864"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains fs.auto" negate="false" test_ref="oval:org.mitre.oval:tst:2870"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File xfs executable">
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2869"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2868"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1519" version="1" class="vulnerability">
      <metadata>
        <title>Plug and Play User Data Validation Vulnerability (WinXP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2120"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="umpnpmgr.dll is less than 5.1.2600.2744" negate="false" test_ref="oval:org.mitre.oval:tst:882"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1518" version="1" class="vulnerability">
      <metadata>
        <title>IE6:S03 Java Proxy COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2087"/>
        <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-26T09:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-04T08:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
        <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
          <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.3790.373" negate="false" test_ref="oval:org.mitre.oval:tst:2335"/>
          </criteria>
          <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
          </criteria>
          <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1517" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="shell32.dll is less than 6.0.2900.2763" negate="false" test_ref="oval:org.mitre.oval:tst:883"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1515" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (WinXP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="cdosys.dll is less than 6.2.4.0" negate="false" test_ref="oval:org.mitre.oval:tst:884"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1514" version="1" class="vulnerability">
      <metadata>
        <title>Element position: Style Change Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0294" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0294"/>
        <description>Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1513" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1512" version="1" class="vulnerability">
      <metadata>
        <title>Windows Virtual DOS Machine Local Privilege Escalation Vulnerability (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>VDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0118"/>
        <description>The component for the Virtual DOS Machine (VDM) subsystem in Windows NT 4.0 and Windows 2000 does not properly validate system structures, which allows local users to access protected kernel memory and execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <modified date="2004-07-19T12:00:00.000-04:00" comment="Modifed without comment">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:885"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="OR" comment="Windows NT or 2000 Installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1511" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 MDAC RDS.Dataspace Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>MDAC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
        <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of msadco.dll is less than 2.71.9053.0" negate="false" test_ref="oval:org.mitre.oval:tst:886"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1510" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2003 Remote Code Execution via Malformed Graphic</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:664 (referenced by tst:888) fixed; was pattern match, now equals.  Thanks to John Hoyland of Centennial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:887) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:36:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.232-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:888"/>
        <criterion comment="the version of excel.exe is less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:887"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:151" version="1" class="vulnerability">
      <metadata>
        <title>Apache Terminal Escape Sequence Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0083" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0083"/>
        <description>Apache 1.3 before 1.3.25 and Apache 2.0 before version 2.0.46 does not filter terminal escape sequences from its access logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences, a different vulnerability than CVE-2003-0020.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.1" negate="false" test_ref="oval:org.mitre.oval:tst:2866"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1509" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2003 Remote Code Execution via Malformed File Format</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:664 (referenced by tst:888) fixed; was pattern match, now equals.  Thanks to John Hoyland of Centennial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:887) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:36:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:20.046-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:888"/>
        <criterion comment="the version of excel.exe is less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:887"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1508" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Server 2003 IE Enhanced Security is installed and set.">
          <criterion comment="Server 2003 IE Enhanced Security (Administror) is installed and set." negate="false" test_ref="oval:org.mitre.oval:tst:1175"/>
          <criterion comment="Server 2003 IE Enhanced Security (User) is installed and set." negate="false" test_ref="oval:org.mitre.oval:tst:1174"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1507" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false" test_ref="oval:org.mitre.oval:tst:1006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1506" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 Java Proxy COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2087"/>
        <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-26T09:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-04T08:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
        </criteria>
        <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
          <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
          </criteria>
          <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
            <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
            <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1505" version="1" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1504" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2003 Remote Code Execution via Malformed Routing Slip</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0009"/>
        <description>Buffer overflow in Microsoft Office 2000 SP3, XP SP3, and other versions and packages, allows user-assisted attackers to execute arbitrary code via a routing slip that is longer than specified by the provided length field, as exploited by malware such as TROJ_MDROPPER.BH and Trojan.PPDropper.E.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:664 (referenced by tst:888) fixed; was pattern match, now equals.  Thanks to John Hoyland of Centennial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:887) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:36:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:19.851-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:888"/>
        <criterion comment="the version of excel.exe is less than 11.0.8012.0" negate="false" test_ref="oval:org.mitre.oval:tst:887"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1503" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 HtmlHelp Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0201" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0201"/>
        <description>Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:150" version="1" class="vulnerability">
      <metadata>
        <title>Apache Terminal Escape Sequence Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020"/>
        <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-17T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="httpd version is less than 2.0.40-21.1" negate="false" test_ref="oval:org.mitre.oval:tst:2866"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:2865"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:15" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File rpc.ttdbserverd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3105"/>
          <criterion comment="Patch 110286-09 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3104"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File rpc.ttdbserverd executable">
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3102"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3101"/>
            <criterion comment="File rpc.ttdbserverd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3100"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1499" version="1" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.2726" negate="false" test_ref="oval:org.mitre.oval:tst:1134"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.2726" negate="false" test_ref="oval:org.mitre.oval:tst:1133"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1498" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Address Bar Spoofing Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1497" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Application Suite has reached End-of-Life</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="MISC" ref_id="http://www.mozilla.org/projects/seamonkey/"/>
        <description>'mozilla.org has launched and delivered SeaMonkey, a community effort to deliver production-quality releases of code derived from the \"Mozilla Application Suite\".  This equates to a cessation in software and security patches for that baseline.  Using an unsupported software represents a high security risk because no fixes or patches will be made available in response to new vulnerabilities.'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite is installed">
          <criterion comment="Mozilla Suite installed" negate="false" test_ref="oval:org.mitre.oval:tst:2441"/>
          <criterion comment="Mozilla Suite is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2440"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1496" version="1" class="vulnerability">
      <metadata>
        <title>Webproxy Integer Overflow in pcre_compile</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="Webproxy is installed" negate="false" test_ref="oval:org.mitre.oval:tst:890"/>
        <criterion comment="Patch PHSS_34163 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:889"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1494" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Garbage-Collection Hazards in jsfun.c</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0293" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0293"/>
        <description>The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1493" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla XML Attribute Name Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0296"/>
        <description>The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox pre-1.5 is installed">
          <criterion comment="Mozilla Firefox pre-1.5" negate="false" test_ref="oval:org.mitre.oval:tst:2445"/>
          <criterion comment="Firefox pre-1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2444"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite is installed">
          <criterion comment="Mozilla Suite installed" negate="false" test_ref="oval:org.mitre.oval:tst:2441"/>
          <criterion comment="Mozilla Suite is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2440"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1492" version="1" class="vulnerability">
      <metadata>
        <title>WinXP (64-bit) Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2606" negate="false" test_ref="oval:org.mitre.oval:tst:916"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1491" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.1.2600.1762 or T2embed.dll &lt;5.1.2600.1762 (WinXP,SP1)">
          <criterion comment="the version of Fontsub.dll is less than 5.1.2600.1762" negate="false" test_ref="oval:org.mitre.oval:tst:892"/>
          <criterion comment="the version of T2embed.dll is less than 5.1.2600.1762" negate="false" test_ref="oval:org.mitre.oval:tst:891"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1490" version="1" class="vulnerability">
      <metadata>
        <title>Win2K,SP4 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:149" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 8 X Font Server Remote Buffer Overrun</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>fs.auto, xfs</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1317" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1317"/>
        <description>Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File fs.auto exists" negate="false" test_ref="oval:org.mitre.oval:tst:2873"/>
          <criterion comment="File xfs exists" negate="false" test_ref="oval:org.mitre.oval:tst:2872"/>
          <criterion comment="Patch 109862-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2871"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains fs.auto" negate="false" test_ref="oval:org.mitre.oval:tst:2870"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File xfs executable">
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2869"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2868"/>
            <criterion comment="File xfs executable" negate="false" test_ref="oval:org.mitre.oval:tst:2867"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1489" version="1" class="vulnerability">
      <metadata>
        <title>Win2k,SP4 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3835.2200" negate="false" test_ref="oval:org.mitre.oval:tst:893"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1488" version="2" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (Windows 2000,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:19.681-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="shell32.dll is less than 5.0.3900.7071" negate="false" test_ref="oval:org.mitre.oval:tst:1086"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1485" version="2" class="vulnerability">
      <metadata>
        <title>Outlook 2000 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-05-31T01:10:00.000-04:00" comment="modified wft-733 - Fixed version operator--was \&quot;greater than\&quot; by mistake.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-05-31T09:44:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:19.398-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:895"/>
        <criterion comment="the version of msmapi32.dll is less than 5.5.3201.0" negate="false" test_ref="oval:org.mitre.oval:tst:894"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1484" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Double Byte Character Parsing Memory Corruption(Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1189"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with double-byte characters, aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1483" version="2" class="vulnerability">
      <metadata>
        <title>IP Source Route Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2379"/>
        <description>Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:19.246-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:07.546-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Tcpip.sys is less than 5.1.2600.1831" negate="false" test_ref="oval:org.mitre.oval:tst:896"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1482" version="1" class="vulnerability">
      <metadata>
        <title>Management Console Directory Traversal Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Solaris Management Console (SMC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1354"/>
        <description>The Solaris Management Console (SMC) in Sun Solaris 8 and 9 generates different 404 error messages when a file does not exist versus when a file exists but is otherwise inacessible, which could allow remote attackers to obtain sensitive information in conjunction with a directory traversal (..) attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-08-22T04:00:00.000-04:00" comment="Affected product changed to Sun Management Console (SMC); mistakenly was .NET framework">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 8 or 9 installed">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          </criteria>
          <criterion comment="Solaris Management Console Web Components (SUNWwbmc) installed" negate="false" test_ref="oval:org.mitre.oval:tst:900"/>
          <criterion comment="Patch 111313-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:899"/>
          <criterion comment="Patch 116807-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:898"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smcboot running" negate="false" test_ref="oval:org.mitre.oval:tst:897"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1480" version="1" class="vulnerability">
      <metadata>
        <title>Heap Overrun in XBM Image Processing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2701" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2701"/>
        <description>Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:148" version="1" class="vulnerability">
      <metadata>
        <title>Evolution GtkHTML DoS via null Pointer Dereference</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GtkHTML</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0541" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0541"/>
        <description>gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gtkhtml version is less than 1.1.9-0.9.1" negate="false" test_ref="oval:org.mitre.oval:tst:2877"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/evolution is executable">
            <criterion comment="/usr/bin/evolution is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2876"/>
            <criterion comment="/usr/bin/evolution is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2875"/>
            <criterion comment="/usr/bin/evolution is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2874"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1479" version="1" class="vulnerability">
      <metadata>
        <title>Integer Overflow in libpng via Malformed PNG Image</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>libpng</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0599" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0599"/>
        <description>Multiple integer overflows in the (1) png_read_png in pngread.c or (2) png_handle_sPLT functions in pngrutil.c or (3) progressive display image reading capability in libpng 1.2.5 and earlier allow remote attackers to cause a denial of service (application crash) via a malformed PNG image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T12:04:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Netscape installed" negate="false" test_ref="oval:org.mitre.oval:tst:901"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1478" version="2" class="vulnerability">
      <metadata>
        <title>Address Bar Spoofing Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2384" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2384"/>
        <description>Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to conduct spoofing and phishing attacks by using a modal browser window in a way that preserves the original address bar and trusted UI of a trusted site, even after the browser has been navigated to a malicious site, aka the "Address Bar Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:19.103-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:07.144-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1477" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Invalid Memory Access Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0034"/>
        <description>Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, aka the MSDTC Invalid Memory Access Vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:18.947-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Msdtctm.dll is less than 2001.12.4720.480" negate="false" test_ref="oval:org.mitre.oval:tst:902"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1475" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false" test_ref="oval:org.mitre.oval:tst:1176"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1472" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.10.20)</title>
        <affected family="unix">
          <platform>HP-UX 10</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.20">
          <criteria operator="AND" comment="700 Series OS Release 10.20">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.10.20" negate="false" test_ref="oval:org.mitre.oval:tst:906"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 10.20">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.10.20" negate="false" test_ref="oval:org.mitre.oval:tst:906"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.10.20) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:905"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:904"/>
        </criteria>
        <criterion comment="Patch PHNE_23948 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:903"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1471" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Spoofing with Translucent Windows</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1725" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1725"/>
        <description>Mozilla Firefox 1.5 before 1.5.0.2 and SeaMonkey before 1.0.1 causes certain windows to become translucent due to an interaction between XUL content windows and the history mechanism, which might allow user-assisted remote attackers to trick users into executing arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:18.763-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1470" version="1" class="vulnerability">
      <metadata>
        <title>Alternate ps Command Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://sunsolve9.sun.com/search/document.do?assetkey=1-26-102215-1&amp;amp;searchclause="/>
        <description>'An unspecified vulnerability in the \"/usr/ucb/ps\" command could allow unprivileged local users to see environment settings for processes of other users.  When the \'e\' flag is used, a low-privileged user can see environment variables and values for processes that belong to root and any other system users. NOTE: \"/usr/bin/ps\" is the default \'ps\' command for most users per the command search path and is not affected by this vulnerability'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-28T09:02:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102215 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109023-05 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:910"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102215 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 120240-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:909"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102215 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109024-05 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:908"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102215 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 120239-01 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:907"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:147" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Shell Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Shell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0070" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0070"/>
        <description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2005-09-26T10:58:00.000-04:00" comment="modified wft-244 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of shell32.dll is less than 5.0.3502.4718" negate="false" test_ref="oval:org.mitre.oval:tst:2878"/>
        <criterion comment="Patch Q313829 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3087"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1468" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="mshtml.dll is less than 6.0.2900.2769" negate="false" test_ref="oval:org.mitre.oval:tst:911"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1467" version="1" class="vulnerability">
      <metadata>
        <title>Samba Encrypted Password DoS</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1318" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1318"/>
        <description>Buffer overflow in samba 2.2.2 through 2.2.6 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an encrypted password that causes the overflow during decryption in which a DOS codepage string is converted to a little-endian UCS2 unicode string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Samba - Usr (SUNWsmbau) installed" negate="false" test_ref="oval:org.mitre.oval:tst:914"/>
          <criterion comment="Patch 114684-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:913"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="smbd running" negate="false" test_ref="oval:org.mitre.oval:tst:912"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1466" version="1" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:959"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1464" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="mshtml.dll is less than 6.0.3790.2541" negate="false" test_ref="oval:org.mitre.oval:tst:1114"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1462" version="1" class="vulnerability">
      <metadata>
        <title>WinXP (64-bit) Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.2.3790.2549 or T2embed.dll &lt;5.2.3790.2549 (WinXP,64-bit and S03,SP1)">
          <criterion comment="the version of Fontsub.dll is less than 5.2.3790.2549" negate="false" test_ref="oval:org.mitre.oval:tst:1098"/>
          <criterion comment="the version of T2embed.dll is less than 5.2.3790.2549" negate="false" test_ref="oval:org.mitre.oval:tst:1097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1461" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX xterm Privilege Escalation Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-26T01:55:00.000-04:00" comment="Updated to CVE-2005-3779.  HP is so vague that it's not completely certain.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHSS_34102 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:915"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1460" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2606" negate="false" test_ref="oval:org.mitre.oval:tst:916"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:146" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT SMB Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0345"/>
        <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Patch Q817606 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2880"/>
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="The version of srv.sys is less than 4.0.1381.7214" negate="false" test_ref="oval:org.mitre.oval:tst:2879"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1459" version="1" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.01)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.22">
            <criteria operator="AND" comment="700 Series OS Release 11.22">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.22">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version less than A.01.11.04">
          <criterion comment="CIFS-Server.CIFS-RUN with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:920"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:919"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:918"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version less than A.01.11.04 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:917"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1458" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false" test_ref="oval:org.mitre.oval:tst:1176"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1456" version="1" class="vulnerability">
      <metadata>
        <title>Outlook 2003 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:922"/>
        <criterion comment="the version of msmapi32.dll is greater than 11.0.6566.0" negate="true" test_ref="oval:org.mitre.oval:tst:921"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1455" version="2" class="vulnerability">
      <metadata>
        <title>Windows NT Certificate Validation Identity Spoofing Vulnerability (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1183"/>
        <description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:49.608-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false" test_ref="oval:org.mitre.oval:tst:1229"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1454" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="mshtml.dll is less than 6.0.3790.418" negate="false" test_ref="oval:org.mitre.oval:tst:923"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1453" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Shared Library Privilege Escalation Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0436" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0436"/>
        <description>Unspecified vulnerability in HP HP-UX B.11.00, B.11.04, and B.11.11 allows local users to gain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_30402 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:924"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1452" version="1" class="vulnerability">
      <metadata>
        <title>MSDTC Unchecked Buffer Permits Remote Code Execution or Privilege Elevation (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSDTC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2119"/>
        <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:959"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1451" version="1" class="vulnerability">
      <metadata>
        <title>IE5 Multiple Event Handler Memory Corruption (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1245" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1245"/>
        <description>Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:145" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT MUP UNC Request Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Multiple UNC Provider (MUP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0151" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0151"/>
        <description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-05-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
        <criterion comment="the version of mup.sys is less than 4.0.1381.7125" negate="false" test_ref="oval:org.mitre.oval:tst:2882"/>
        <criterion comment="Patch Q312895 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2881"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1448" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 COM object Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
        <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of shell32.dll is less than 6.0.2900.2869" negate="false" test_ref="oval:org.mitre.oval:tst:925"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1446" version="1" class="vulnerability">
      <metadata>
        <title>IE5 COM Object Instantiation Memory Corruption (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1186"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:927"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3839.2200" negate="false" test_ref="oval:org.mitre.oval:tst:926"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1445" version="1" class="vulnerability">
      <metadata>
        <title>SMC TRACE HTTP Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>Solaris Management Console</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3398"/>
        <description>The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the HTTP TRACE method, which could allow remote attackers to obtain sensitive information such as cookies and authentication data from HTTP headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 111313-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:933"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 111314-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:932"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116807-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:931"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 116808-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:930"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 121308-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:929"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102016 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 121309-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:928"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1443" version="1" class="vulnerability">
      <metadata>
        <title>Firefox/Mozilla Suite about: Scheme Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2706" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2706"/>
        <description>Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as about:mozilla.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:144" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 SNMPv1 Trap Handling DoS and Privilege Escalation (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012"/>
        <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
          </criteria>
          <criterion comment="the version of snmp.exe is less than 5.0.2195.4919" negate="false" test_ref="oval:org.mitre.oval:tst:2883"/>
          <criterion comment="Patch Q314147 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2959"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1439" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1119"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1118"/>
        </criteria>
        <criterion comment="Patch PHNE_23950 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:934"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1435" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false" test_ref="oval:org.mitre.oval:tst:1006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1434" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 DirectShow Malicious avi File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
        <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="DirectX packaged with Windows XP,SP1 has DirectShow Vulnerability">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.4.2600.0" negate="false" test_ref="oval:org.mitre.oval:tst:941"/>
          <criterion comment="the version of Quartz.dll is less than 6.4.2600.1738" negate="false" test_ref="oval:org.mitre.oval:tst:940"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 8 has DirectShow Vulnerability">
          <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 9 has DirectShow Vulnerability">
          <criterion comment="DirectX 9.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1120"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1433" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-28T10:07:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-29T11:27:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-07T07:17:00.000-04:00" comment="New definition.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-25T07:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Gdi32.dll is less than 5.1.2600.2818" negate="false" test_ref="oval:org.mitre.oval:tst:942"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1431" version="1" class="vulnerability">
      <metadata>
        <title>Win2K Graphics Rendering Engine Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4560" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4560"/>
        <description>The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-07T07:15:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7073" negate="false" test_ref="oval:org.mitre.oval:tst:943"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:143" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft IE Encoded Characters Information Disclosure</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1186" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1186"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka "Encoded Characters Information Disclosure."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2722.900" negate="false" test_ref="oval:org.mitre.oval:tst:2884"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1429" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX envd Local Execution of Privileged Code (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>envd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3564"/>
        <description>envd daemon in HP-UX B.11.00 through B.11.11 allows local users to obtain privileges via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="OS-Core.CORE-ENG-A-MAN or OS-Core.UX-CORE (B.11.00) is installed">
          <criterion comment="OS-Core.CORE-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:946"/>
          <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:945"/>
        </criteria>
        <criterion comment="Patch PHCO_33989 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:944"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1427" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP IIS WebDAV Message Handler Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0718"/>
        <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T11:09:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of httpext.dll exists">
          <criteria operator="AND" comment="Service pack 1 and the version of httpext.dll is less than 6.0.2600.1579">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of httpext.dll is less than 6.0.2600.1579" negate="false" test_ref="oval:org.mitre.oval:tst:948"/>
          </criteria>
          <criteria operator="AND" comment="no service pack and the version of httpext.dll is less than 6.0.2600.165">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of httpext.dll is less than 6.0.2600.165" negate="false" test_ref="oval:org.mitre.oval:tst:947"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB824151 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:984"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1426" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2831" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2831"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, aka a variant of the "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2127.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false" test_ref="oval:org.mitre.oval:tst:1006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1425" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP IGMP v3 Denial of Service (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0021"/>
        <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Tcpip.sys is less than 5.1.2600.2827 (XP,SP2)" negate="false" test_ref="oval:org.mitre.oval:tst:949"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1424" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 DirectShow Malicious avi File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
        <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="DirectX packaged with Windows Server 2003 has DirectShow Vulnerability">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.4.3790.0" negate="false" test_ref="oval:org.mitre.oval:tst:951"/>
          <criterion comment="the version of Quartz.dll is less than 6.4.3790.399" negate="false" test_ref="oval:org.mitre.oval:tst:950"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 8 has DirectShow Vulnerability">
          <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 9 has DirectShow Vulnerability">
          <criterion comment="DirectX 9.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1120"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1423" version="2" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:18.563-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:06.736-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.536" negate="false" test_ref="oval:org.mitre.oval:tst:952"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1420" version="2" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (Win2K,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:18.350-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="cdosys.dll is less than 6.1.3940.42" negate="false" test_ref="oval:org.mitre.oval:tst:953"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:142" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed OVAL142, covered by OVAL2022</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="Windows NT Service Pack 6a is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2887"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" negate="false" test_ref="oval:org.mitre.oval:tst:2886"/>
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1418" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Word2003 Malformed Object Pointer Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2492"/>
        <description>Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:18.173-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:06.254-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of winword.exe is less than 11.0.8026.0" negate="false" test_ref="oval:org.mitre.oval:tst:954"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1417" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Table Conversion Vulnerability (NT 4.0 Terminal Server)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria. 1) dropped explicit check for Hotfix kb885836, 2) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="the version of wordpad.exe is less than 4.0.1381.33598" negate="false" test_ref="oval:org.mitre.oval:tst:955"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1416" version="1" class="vulnerability">
      <metadata>
        <title>FTP Download Destination Tampering Vulnerability (Windows XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2126"/>
        <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="msieftp.dll is less than 6.0.2800.1724" negate="false" test_ref="oval:org.mitre.oval:tst:956"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1415" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1414" version="2" class="vulnerability">
      <metadata>
        <title>HTML Decoding Memory Corruption Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2382"/>
        <description>Heap-based buffer overflow in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via crafted UTF-8 encoded HTML that results in size discrepancies during conversion to Unicode, aka "HTML Decoding Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:18.013-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:05.786-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
        <criterion comment="the version of mshtml.dll is less than 5.0.3841.1900" negate="false" test_ref="oval:org.mitre.oval:tst:957"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1413" version="1" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.374">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:959"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.374" negate="false" test_ref="oval:org.mitre.oval:tst:958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1412" version="1" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00619550"/>
        <description>'An undisclosed vulnerability has been identified in /sbin/passwd which could be exploited to create a Denial of Service condition..'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:961"/>
        <criterion comment="Patch PHCO_33219 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:960"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1411" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2002 Remote Code Execution via Malformed File Format</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2377) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:1360 (referenced by tst:2378) fixed: was pattern match, now equals.  Thanks to John Hoyland of Centenial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:17.757-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2378"/>
        <criterion comment="the version of excel.exe is less than 10.0.6789.0" negate="false" test_ref="oval:org.mitre.oval:tst:2377"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:141" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Internet Explorer MIME Hack</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0154"/>
        <description>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-07-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T12:00:00.000-04:00" comment="Added the configuration check to see if file downloads are enabled by the current user when local machine settings are not in use.  Changed the status from ACCEPTED to INTERIM">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Internet Explorer 5.01 Installed">
            <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3070"/>
            <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3069"/>
            <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3068"/>
            <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3067"/>
            <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3066"/>
            <criterion comment="Internet Explorer 5.01 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3065"/>
          </criteria>
          <criterion comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" negate="false" test_ref="oval:org.mitre.oval:tst:2892"/>
          <criterion comment="the patch q290108 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2891"/>
          <criterion comment="the patch q295106 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2890"/>
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3019"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="file downloads are enabled">
            <criteria operator="AND" comment="current user settings are being used and file downloads are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="file downloads are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2889"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and file downloads are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="file downloads are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2888"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1409" version="1" class="vulnerability">
      <metadata>
        <title>PC Netlink 2.0 Privilege Escalation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Solaris Management Console</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-4552" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4552"/>
        <description>The (1) slsmgr and (2) slsadmin programs in Sun Solaris PC NetLink 2.0 create temporary files insecurely, which allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
        <criterion comment="the SUNWlzas package (for slsadmin) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:963"/>
        <criterion comment="Patch 121332-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:962"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1407" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23-IPSEC)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.22">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
        </criteria>
        <criterion comment="IPSec.IPSEC2-KRN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:966"/>
        <criteria operator="OR" comment="IPSec.IPSEC2-KRN version is under A.2.00.01 or TOUR version is under 3.0 or patch PHNE_32606 is not installed">
          <criterion comment="IPSec.IPSEC2-KRN with version less than A.2.00.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:965"/>
          <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:964"/>
          <criterion comment="Patch PHNE_32606 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1441"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1406" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="cdosys.dll is less than 6.1.1002.0" negate="false" test_ref="oval:org.mitre.oval:tst:967"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1405" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Print Spooler Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Print Spooler Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1984"/>
        <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:969"/>
        <criterion comment="the version of Spoolsv.exe is less than 5.2.3790.346" negate="false" test_ref="oval:org.mitre.oval:tst:968"/>
        <criterion comment="the patch KB896423 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1245"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1402" version="1" class="vulnerability">
      <metadata>
        <title>Winamp Hostname Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Winamp</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0476"/>
        <description>Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T08:59:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of winamp is less than or equal 5.12" negate="false" test_ref="oval:org.mitre.oval:tst:970"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1401" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2000 Remote Code Execution via Malformed Graphic</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0030" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0030"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:1110) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:17.562-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8938" negate="false" test_ref="oval:org.mitre.oval:tst:1110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:140" version="1" class="vulnerability">
      <metadata>
        <title>Default Registry Permissions on the MTS Package Admin Key</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Transaction Server (MTS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0047"/>
        <description>The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the "Registry Permissions" vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="AND" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
            <criterion comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" negate="false" test_ref="oval:org.mitre.oval:tst:2896"/>
            <criterion comment="Windows NT 4.0 Security Roll-up Package" negate="true" test_ref="oval:org.mitre.oval:tst:3036"/>
          </criteria>
          <criteria operator="AND" comment="For Terminal Server">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" negate="false" test_ref="oval:org.mitre.oval:tst:2895"/>
          </criteria>
          <criterion comment="Patch Q265714 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2894"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="MTS Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2893"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:14" version="1" class="vulnerability">
      <metadata>
        <title>Sun Solaris 8 XSun Color Database File Heap Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>Xsun</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0158"/>
        <description>Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color database) command line argument.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-08-23T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File Xsun exists" negate="false" test_ref="oval:org.mitre.oval:tst:3109"/>
          <criterion comment="Patch 108652-52 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3108"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Xsun SGID and executable">
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3107"/>
            <criterion comment="File Xsun SGID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3106"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:139" version="1" class="vulnerability">
      <metadata>
        <title>Default Registry Permissions on SNMP Parameters</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Simple Network Management Protocol (SNMP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0046" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0046"/>
        <description>The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the "Registry Permissions" vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="AND" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
            <criterion comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" negate="false" test_ref="oval:org.mitre.oval:tst:2896"/>
            <criterion comment="Windows NT 4.0 Security Roll-up Package" negate="true" test_ref="oval:org.mitre.oval:tst:3036"/>
          </criteria>
          <criteria operator="AND" comment="For Terminal Server">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" negate="false" test_ref="oval:org.mitre.oval:tst:2895"/>
          </criteria>
          <criterion comment="Patch Q265714 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2894"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the SNMP service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2958"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:138" version="1" class="vulnerability">
      <metadata>
        <title>Evolution GtkHTML DoS via Malformed Message</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GtkHTML</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0133" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0133"/>
        <description>GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-02T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gtkhtml version is less than 1.1.9-0.9" negate="false" test_ref="oval:org.mitre.oval:tst:2897"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:137" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS HTTP Header Field Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0150"/>
        <description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:136" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Java Virtual Machine Security Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Virtual Machine (VM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0111" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0111"/>
        <description>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka "Flaw in Microsoft VM Could Enable System Compromise."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of msjava.dll is less than 5.0.3810.0" negate="false" test_ref="oval:org.mitre.oval:tst:2898"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:135" version="1" class="vulnerability">
      <metadata>
        <title>GnuPG Invalid User ID Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GnuPG</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0255"/>
        <description>The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-19T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="gnupg version is less than 1.2.1-4" negate="false" test_ref="oval:org.mitre.oval:tst:2901"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gnupg is executable">
            <criterion comment="/usr/bin/gnupg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2900"/>
            <criterion comment="/usr/bin/gnupg is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2899"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1349" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 IE HTML Help ActiveX control Cross Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>HTML Help ActiveX Control</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1043" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1043"/>
        <description>Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the "Related Topics" command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed, as demonstrated using "writehta.txt" and the ADODB recordset, which saves a .HTA file to the local system, aka the "HTML Help ActiveX control Cross Domain Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-12T08:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the patch kb890175 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:972"/>
          <criterion comment="the version of hhctrl.ocx is less than 5.2.3790.233" negate="false" test_ref="oval:org.mitre.oval:tst:971"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1348" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 XBL Script Security Bypass Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2261"/>
        <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1347" version="1" class="vulnerability">
      <metadata>
        <title>FreeRADIUS Ascend-Send-Secret Server Crash</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>FreeRADIUS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0938" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0938"/>
        <description>FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (server crash) by sending an Ascend-Send-Secret attribute without the required leading packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-22T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="FreeRADIUS rpm older than 1.0.1-1" negate="false" test_ref="oval:org.mitre.oval:tst:974"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="radiusd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:973"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1346" version="1" class="vulnerability">
      <metadata>
        <title>Apache mod_ssl CRL off-by-one DoS</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1268"/>
        <description>Off-by-one error in the mod_ssl Certificate Revocation List (CRL) verification callback in Apache, when configured to use a CRL, allows remote attackers to cause a denial of service (child process crash) via a CRL that causes a buffer overflow of one null byte.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1345" version="1" class="vulnerability">
      <metadata>
        <title>Leaking GSSAPI Credentials Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2798"/>
        <description>sshd in OpenSSH before 4.2, when GSSAPIDelegateCredentials is enabled, allows GSSAPI credentials to be delegated to clients who log in using non-GSSAPI methods, which could cause those credentials to be exposed to untrusted users or hosts.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1032"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1344" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT Task Scheduler Stack Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0212"/>
        <description>Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-14T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-04T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-14T05:00:00.000-04:00" comment="modified wrt-347 - Changed the service pack comparison from greater than or equal to a pattern match.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criterion comment="Win2K/XP/2003 service pack 6 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1469"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        <criterion comment="the version of mstask.dll is less than 4.71.1979.1" negate="false" test_ref="oval:org.mitre.oval:tst:976"/>
        <criterion comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:975"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1340" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 (64-bit) File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:134" version="2" class="vulnerability">
      <metadata>
        <title>Windows Script Engine Heap Overflow (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Script Engine for Jscript</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0010"/>
        <description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-11-02T12:00:00.000-04:00"/>
            <status_change date="2004-11-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-01-06T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <modified date="2006-09-06T15:59:00.000-04:00" comment="changed criteria operator to OR when checking file version and patch installation">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-27T12:28:40.970-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="jscript.dll version is 5.1, 5.5, or 5.6">
          <criterion comment="the version of jscript.dll is less than 5.1.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2907"/>
          <criterion comment="the version of jscript.dll is less than 5.5.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2906"/>
          <criterion comment="the version of jscript.dll is less than 5.6.0.8513" negate="false" test_ref="oval:org.mitre.oval:tst:2905"/>
        </criteria>
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criteria operator="OR" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6" negate="true">
          <criterion comment="the patch js56nen.exe (5.6.0.8513 version) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2904"/>
          <criterion comment="the patch js56nen.exe (5.1.0.8513 version) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2903"/>
          <criterion comment="the patch js56nen.exe (5.5.0.8513 version) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2902"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1339" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Integer overflows in E4X, SVG, and Canvas Features</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0297" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0297"/>
        <description>Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSurface::Init in SVG, and (3) nsCanvasRenderingContext2D.cpp in Canvas.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-07T06:13:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.1">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" negate="true" test_ref="oval:org.mitre.oval:tst:2446"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1338" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1337" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990"/>
        <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1336" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Address Bar Spoofing Vulnerability (Win2K/XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1192"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability."  NOTE: this is a different vulnerability than CVE-2006-1626.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1335" version="1" class="vulnerability">
      <metadata>
        <title>IE6 for XP,SP2 JPEG Image Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1988"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false" test_ref="oval:org.mitre.oval:tst:2331"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1334" version="1" class="vulnerability">
      <metadata>
        <title>IE6 for Server 2003 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-21T10:35:00.000-04:00" comment="modified wrt-158 - removed note">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-04-21T12:00:00.000-04:00" comment="modified wrt-158 - removed value to check against">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <modified date="2005-05-10T12:00:00.000-04:00" comment="modified wrt-51 - Comment updated to indicate IE 6.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.259" negate="false" test_ref="oval:org.mitre.oval:tst:978"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="Check for Drag&amp;Drop enabled and the patch kb834707(wildcard*)  missing">
            <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
            <criterion comment="the patch kb834707(wildcard*) is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:977"/>
          </criteria>
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1333" version="1" class="vulnerability">
      <metadata>
        <title>WU-FTPD "glob-*" Remote DoS Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0256"/>
        <description>The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir copmmand.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="INETSVCS-RUN without patch PHNE_34543 or later, OR WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed">
          <criteria operator="AND" comment="INETSVCS-RUN without patch PHNE_34543 or later">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:981"/>
            <criterion comment="Patch PHNE_34543 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:980"/>
          </criteria>
          <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:979"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1332" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Certificate Validation Identity Spoofing Vulnerability (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0862"/>
        <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-03-07T12:00:00.000-04:00" comment="modified wrt-222 - changed pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
        </criteria>
        <criterion comment="the version of cryptdlg.dll is less than 5.0.1558.6608" negate="false" test_ref="oval:org.mitre.oval:tst:982"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1331" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Word 2000 Font Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office 2000 SP3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0564"/>
        <description>Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-21T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria to check for Word 2000 instead of MS Office SP3.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-20T07:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:17.321-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8930" negate="false" test_ref="oval:org.mitre.oval:tst:983"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1330" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS WebDAV Message Handler Denial of Service Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0718" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0718"/>
        <description>The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a large number of attributes.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-13T09:30:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2004-10-13T01:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-27T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-11-17T10:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp5 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of httpext.dll is less than 5.0.2195.6958" negate="false" test_ref="oval:org.mitre.oval:tst:985"/>
          <criterion comment="the patch KB824151 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:984"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="WebDav is disabled(for iis 5.0)" negate="true" test_ref="oval:org.mitre.oval:tst:2953"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:133" version="1" class="vulnerability">
      <metadata>
        <title>GNU Ghostscript -dSAFER Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GNU Ghostscript</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0354" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0354"/>
        <description>Unknown vulnerability in GNU Ghostscript before 7.07 allows attackers to execute arbitrary commands, even when -dSAFER is enabled, via a PostScript file that causes the commands to be executed from a malicious print job.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="ghostscript version is less than 7.05-32.1" negate="false" test_ref="oval:org.mitre.oval:tst:2911"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/gs is executable">
            <criterion comment="/usr/bin/gs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2910"/>
            <criterion comment="/usr/bin/gs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2909"/>
            <criterion comment="/usr/bin/gs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2908"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1329" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Open Remote Code Execution Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2122"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="shell32.dll is less than 6.0.2800.1751" negate="false" test_ref="oval:org.mitre.oval:tst:1149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1328" version="1" class="vulnerability">
      <metadata>
        <title>Plug and Play User Data Validation Vulnerability (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2120"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="umpnpmgr.dll is less than 5.1.2600.1734" negate="false" test_ref="oval:org.mitre.oval:tst:986"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1327" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2000 Remote Code Execution via Malformed Record</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0031" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0031"/>
        <description>Stack-based buffer overflow in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed record with a modified length value, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:1110) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:17.070-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8938" negate="false" test_ref="oval:org.mitre.oval:tst:1110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1326" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Java Proxy COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2087" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2087"/>
        <description>Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, as demonstrated using the JVIEW Profiler (Javaprxy.dll).  NOTE: the researcher says that the vendor could not reproduce this problem.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-18T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T04:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-09-08T04:00:00.000-04:00" comment="modified wet-2 - Corrected structure of path components.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-09-28T01:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="This is fixed by MS05-038, which provides better test criteria. Changed test criteria accordingly.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3831.1800" negate="false" test_ref="oval:org.mitre.oval:tst:2664"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1325" version="1" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1323" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 MDAC RDS.Dataspace Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>MDAC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
        <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of msadco.dll is less than 2.80.1062.0" negate="false" test_ref="oval:org.mitre.oval:tst:987"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1321" version="2" class="vulnerability">
      <metadata>
        <title>Windows Kernel LPC Privilege Escalation Vulnerability (NT 4.0)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0893" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0893"/>
        <description>The Local Procedure Call (LPC) interface of the Windows Kernel for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the lengths of messages sent to the LPC port, which allows local users to gain privileges, aka "Windows Kernel Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-12-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T09:25:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it references Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:49.402-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criteria operator="OR" comment="Windows NT server product option">
            <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
            <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
          </criteria>
        </criteria>
        <criterion comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" negate="false" test_ref="oval:org.mitre.oval:tst:988"/>
        <criterion comment="the patch kb885835is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2622"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:132" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS ASP Server-Side Include Function Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0149"/>
        <description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of w3svc.dll is less than 4.2.775.1" negate="false" test_ref="oval:org.mitre.oval:tst:3096"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="asp.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3092"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1319" version="1" class="vulnerability">
      <metadata>
        <title>IE6:XP,SP2 Web Folder Behaviors Cross-Domain Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false" test_ref="oval:org.mitre.oval:tst:2331"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1317" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false" test_ref="oval:org.mitre.oval:tst:1176"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1316" version="1" class="vulnerability">
      <metadata>
        <title>Exchange Server 5.0 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Mdbmsg.dll greater than or equal 5.0.1460.9 (Exchange Server 5.0,SP2 is installed)." negate="false" test_ref="oval:org.mitre.oval:tst:990"/>
        <criterion comment="the version of Mdbmsg.dll is less than 5.0.1462.22" negate="false" test_ref="oval:org.mitre.oval:tst:989"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1315" version="2" class="vulnerability">
      <metadata>
        <title>Exchange Server 2000 when running Outlook Web Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1193"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:16.925-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:05.307-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2000,SP3 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:992"/>
        <criterion comment="mdbmsg.dll is less than 6.0.6618.4" negate="false" test_ref="oval:org.mitre.oval:tst:991"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1313" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox and Mozilla Javascript Dialog Box Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2268"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1311" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox InstallTrigger Callback Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2263"/>
        <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1310" version="1" class="vulnerability">
      <metadata>
        <title>TCP/IP IGMP v3 Denial of Service (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0021" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0021"/>
        <description>Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang) via certain malformed IGMP packets, aka the "IGMP v3 DoS Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Tcpip.sys is less than 5.2.3790.468 (S03-Gold)" negate="false" test_ref="oval:org.mitre.oval:tst:993"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:131" version="1" class="vulnerability">
      <metadata>
        <title>Heap Overflow in Solaris 7 xlock</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>xlock</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0652"/>
        <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File xlock exists" negate="false" test_ref="oval:org.mitre.oval:tst:3130"/>
          <criterion comment="Patch 108376-30 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2912"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File xlock SUID and executable">
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3128"/>
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3127"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1308" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 Security Zone Restriction Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0054" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0054"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a malicious hostname, aka the "URL Decoding Zone Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3825.700" negate="false" test_ref="oval:org.mitre.oval:tst:994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1307" version="1" class="vulnerability">
      <metadata>
        <title>Firefox/Mozilla Suite JavaScript Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2705" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2705"/>
        <description>Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1306" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Media Player PNG Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1244" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1244"/>
        <description>Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-16T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-02-22T10:00:00.000-04:00" comment="Added vulnerable configuration">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-09T07:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified objects 733, 734, 735, 736, 738, and 739 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:38.693-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Media Player 9.0 installed" negate="false" test_ref="oval:org.mitre.oval:tst:1004"/>
          <criterion comment="the version of wmp.dll is les than 9.0.0.3250" negate="false" test_ref="oval:org.mitre.oval:tst:1003"/>
          <criterion comment="The patch KB885492 is installed on Windows XP" negate="true" test_ref="oval:org.mitre.oval:tst:1002"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="The files .asx, .wax, .wvx, .wpl, .wmx, .wms, .wmz EXIST">
            <criterion comment=".asx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:1001"/>
            <criterion comment=".wax EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:1000"/>
            <criterion comment=".wvx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:999"/>
            <criterion comment=".wpl EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:998"/>
            <criterion comment=".wmx EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:997"/>
            <criterion comment=".wms EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:996"/>
            <criterion comment=".wmz EXISTS" negate="false" test_ref="oval:org.mitre.oval:tst:995"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1304" version="1" class="vulnerability">
      <metadata>
        <title>Animated Cursor Denial of Service (XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Animated Cursor</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1305" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1305"/>
        <description>The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP SP1 OR Windows XP 64-bit SP1 is installed">
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of user32.dll is less than 5.1.2600.1617" negate="false" test_ref="oval:org.mitre.oval:tst:1005"/>
        <criterion comment="the patch kb891711 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2807"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1303" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 (64-bit) IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:130" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 HTR ISAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0071" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0071"/>
        <description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
          <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
          <criterion comment="the version of w3svc.dll is less than 5.0.2195.5269" negate="false" test_ref="oval:org.mitre.oval:tst:3080"/>
          <criterion comment="Patch Q319733 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3095"/>
          <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
          <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="ism.dll mapping exists" negate="false" test_ref="oval:org.mitre.oval:tst:3057"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:13" version="2">
      <metadata>
        <title>Buffer Overrun in HTML Help Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3357" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3357" source="CVE"/>
        <description>Heap-based buffer overflow in HTML Help ActiveX control (hhctrl.ocx) in Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code by repeatedly setting the Image field of an Internet.HHCtrl.1 object to certain values, possibly related to improper escaping and long strings.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:38.073-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:21.058-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:44"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:44"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2744" test_ref="oval:org.mitre.oval:tst:15"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2744" test_ref="oval:org.mitre.oval:tst:15"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.558" test_ref="oval:org.mitre.oval:tst:44"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2744" test_ref="oval:org.mitre.oval:tst:15"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1299" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2802" negate="false" test_ref="oval:org.mitre.oval:tst:1006"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1297" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 TAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Telephony Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-11T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criteria operator="OR" comment="a vulnerable version of tapisrv.dll exists">
            <criteria operator="AND" comment="for 32-bit or 64-bit (itanium architecture) Windows gold edition a vulnerable version of tapisrv.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of tapisrv.dll is less than 5.2.3790.366" negate="false" test_ref="oval:org.mitre.oval:tst:1007"/>
            </criteria>
            <criteria operator="AND" comment="for 32-bit or 64-bit (itanium architecture) Windows with SP1 a vulnerable version of tapisrv.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false" test_ref="oval:org.mitre.oval:tst:1193"/>
            </criteria>
            <criteria operator="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of tapisrv.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false" test_ref="oval:org.mitre.oval:tst:1193"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb893756 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1192"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the Telephony service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1191"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1296" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Tag Memory Corruption (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1188"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1295" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Denial of Service Vulnerability (XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1184"/>
        <description>Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain length, which causes an out-of-range memory access, aka the MSDTC Denial of Service Vulnerability.  NOTE: this is a variant of CVE-2005-2119.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of Msdtctm.dll is less than 2001.12.4414.65" negate="false" test_ref="oval:org.mitre.oval:tst:1008"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1294" version="2" class="vulnerability">
      <metadata>
        <title>IFRAME Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1050" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1050"/>
        <description>Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-01-12T05:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T05:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T04:00:00.000-04:00" comment="modified wrt-24 - corrected hotfix key">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-06-08T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:36.634-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        </criteria>
        <criteria operator="OR" comment="patch kb889293 is installed (hotfix or ID)" negate="true">
          <criterion comment="the patch kb889293 is installed (Installed Components key)" negate="false" test_ref="oval:org.mitre.oval:tst:1010"/>
          <criterion comment="the patch kb889293 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1009"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1291" version="2" class="vulnerability">
      <metadata>
        <title>Windows Explorer Web View Script Injection Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2117" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2117"/>
        <description>Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.554-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="shell32.dll is less than 5.0.3900.7071" negate="false" test_ref="oval:org.mitre.oval:tst:1086"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1290" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Tag Memory Corruption (Win2K/WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1188"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1543" negate="false" test_ref="oval:org.mitre.oval:tst:2332"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:129" version="1" class="vulnerability">
      <metadata>
        <title>GDM X Display Manager Authorization Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0549"/>
        <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gdm version is less than 2.4.1.3-5.1" negate="false" test_ref="oval:org.mitre.oval:tst:2936"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1289" version="2" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.291-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="netman.dll is less than 5.0.2195.7061" negate="false" test_ref="oval:org.mitre.oval:tst:1011"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1288" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Land Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0688"/>
        <description>Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Land" vulnerability (CVE-1999-0016).</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-04-27T12:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-06T04:13:00.000-04:00" comment="Replaced reference to var:200 with reference to var:201 in obj:588 since tcpip.sys is located in \system32\drivers and not \system32.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:49.217-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Tcpip.sys is less than 5.0.2195.7035" negate="false" test_ref="oval:org.mitre.oval:tst:1012"/>
        <criterion comment="the patch KB893066 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2353"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1287" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla IDN heap overrun using soft-hyphens</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2871"/>
        <description>Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-27T08:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, 11.22, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.22">
            <criteria operator="AND" comment="700 Series OS Release 11.22">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.22">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.22" negate="false" test_ref="oval:org.mitre.oval:tst:1015"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="Mozilla is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1014"/>
        <criterion comment="Mozilla v1.7.12 (1.7.12.0.00) or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1013"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1284" version="1" class="vulnerability">
      <metadata>
        <title>FTP Download Destination Tampering Vulnerability (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2126"/>
        <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="msieftp.dll is less than 6.0.3790.383" negate="false" test_ref="oval:org.mitre.oval:tst:1016"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1283" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1200"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1281" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox InstallTrigger Callback Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2263"/>
        <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1280" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of mscms.dll is less than 5.0.2195.7054" negate="false" test_ref="oval:org.mitre.oval:tst:1017"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1279" version="1" class="vulnerability">
      <metadata>
        <title>Windows 98 Program Group Converter Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <product>Program Group Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0572" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0572"/>
        <description>Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T03:38:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 98 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1345"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1276" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.00) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2376"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2375"/>
        </criteria>
        <criterion comment="Patch PHNE_23949 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1018"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1272" version="1" class="vulnerability">
      <metadata>
        <title>Object Spoofing using XBL &lt;implements> Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2704" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2704"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1271" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Object Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0550" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0550"/>
        <description>Buffer overflow in Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to cause a denial of service (i.e., system crash) via a malformed request, aka "Object Management Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-05-04T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" negate="false" test_ref="oval:org.mitre.oval:tst:1025"/>
        <criterion comment="the patch KB890859 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:127" version="1" class="vulnerability">
      <metadata>
        <title>RPCSS DCOM Buffer Overflow (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0528" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0528"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0715.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="DCOM is enabled on systems with SP3 or later">
            <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3079"/>
            <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1269" version="1" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1200"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1268" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla Javascript Dialog Box Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2268"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1267" version="1" class="vulnerability">
      <metadata>
        <title>Win2k,SP4 DirectShow Malicious avi File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
        <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="DirectX packaged with Windows 2000,SP4 has DirectShow Vulnerability">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="SP4 or later Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3073"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.1.9.726" negate="false" test_ref="oval:org.mitre.oval:tst:1027"/>
          <criterion comment="the version of Quartz.dll is less than 6.1.9.732" negate="false" test_ref="oval:org.mitre.oval:tst:1026"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 8 has DirectShow Vulnerability">
          <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 9 has DirectShow Vulnerability">
          <criterion comment="DirectX 9.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1120"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1266" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Crashes with Evidence of Memory Corruption (Firefox Regression Fix)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1790"/>
        <description>A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the InstallTrigger.install method, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:16.094-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1029"/>
          <criterion comment="Firefox version 1.0.7 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1028"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1265" version="1" class="vulnerability">
      <metadata>
        <title>WU-FTPD "glob-*" Remote DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0256" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0256"/>
        <description>The wu_fnmatch function in wu_fnmatch.c for wu-fptd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir copmmand.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_34306 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1030"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1264" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Kernel Debugger-based Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0112"/>
        <description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-31T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the patch Q811493 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2885"/>
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="The version of Ntoskrnl.exe is less than 5.1.2600.1151" negate="false" test_ref="oval:org.mitre.oval:tst:1031"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1263" version="1" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (64-bit Windows XP and Server 2003,Unpatched)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.419" negate="false" test_ref="oval:org.mitre.oval:tst:2436"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1262" version="1" class="vulnerability">
      <metadata>
        <title>zlib Compression Remote DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>SecureShell</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2096" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2096"/>
        <description>zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Secure_Shell.SECURE_SHELL is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1033"/>
        <criterion comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1032"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1261" version="1" class="vulnerability">
      <metadata>
        <title>COM+ Memory Structures Process Permits Remote Code Execution (64-bit XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1978" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1978"/>
        <description>COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1260" version="1" class="vulnerability">
      <metadata>
        <title>Integer Overflow in libgd2</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libgd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0990"/>
        <description>Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="AND" comment="libgd or libgd-devel RPM is earlier than 0:1.8.4-12.3.1">
          <criterion comment="libgd RPM is earlier than 0:1.8.4-12.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1085"/>
          <criterion comment="libgd-devel RPM is earlier than 0:1.8.4-12.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1084"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:126" version="1" class="vulnerability">
      <metadata>
        <title>IE v6.0 Improper Cross Domain Security Validation with Dialog Box</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1326" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1326"/>
        <description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka "Improper Cross Domain Security Validation with dialog box."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-27T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of mshtml.dll is less than 6.0.2723.2500" negate="false" test_ref="oval:org.mitre.oval:tst:3003"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1258" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox and Mozilla DOM Node Spoofing</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:2482"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1256" version="1" class="vulnerability">
      <metadata>
        <title>Windows Media Player 8 Bitmap Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0006" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0006"/>
        <description>Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted bitmap (.BMP) file that specifies a size of 0 but contains additional data.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1035"/>
        <criterion comment="the version of Wmpui.dll is less than 8.0.0.4495" negate="false" test_ref="oval:org.mitre.oval:tst:1034"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1255" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Web Client Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Web Client Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1207"/>
        <description>Buffer overflow in the Web Client service in Microsoft Windows XP and Windows Server 2003 allows remote authenticated users to execute arbitrary code via a crafted WebDAV request containing special parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.1673" negate="false" test_ref="oval:org.mitre.oval:tst:1036"/>
        <criterion comment="the patch kb896426 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2391"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1254" version="1" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Windows XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="netman.dll is less than 5.1.2600.1733" negate="false" test_ref="oval:org.mitre.oval:tst:1037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1253" version="1" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (Win2k,SP4)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.0.2195.7059">
          <criterion comment="the version of ole32.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2568"/>
          <criterion comment="the version of rpcss.dll is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:2567"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1251" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Cross-Domain Information Disclosure Vulnerability (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1191" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1191"/>
        <description>Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1250" version="1" class="vulnerability">
      <metadata>
        <title>Network Connection Manager Interruption of Service (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2307" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2307"/>
        <description>netman.dll in Microsoft Windows Connections Manager Library allows local users to cause a denial of service (Network Connections Service crash) via a large integer argument to a particular function, aka "Network Connection Manager Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="netman.dll is less than 5.2.3790.396" negate="false" test_ref="oval:org.mitre.oval:tst:1038"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1247" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Privilege Escalation Using a JavaScript Function's Cloned Parent</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1734" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1734"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using the Object.watch method to access the "clone parent" internal function.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.909-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1246" version="1" class="vulnerability">
      <metadata>
        <title>VirusVault CGI Byterange Request DoS</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="700 Series OS Release 11.04">
          <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
          <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
        </criteria>
        <criterion comment="VirusVault is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1040"/>
        <criterion comment="Patch PHSS_34123 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1039"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1245" version="1" class="vulnerability">
      <metadata>
        <title>gedit Format String Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gedit</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1686" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1686"/>
        <description>Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename.  NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be configured to provide a file name as an argument to gedit, so there is a valid attack that crosses security boundaries.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gedit RPM earlier than 1:2.2.2-4rhel3" negate="false" test_ref="oval:org.mitre.oval:tst:1042"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/gedit is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1041"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1244" version="2" class="vulnerability">
      <metadata>
        <title>Plug and Play User Data Validation Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2120" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2120"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a registry key name, which triggers the overflow in a wsprintfW function call.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.640-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="umpnpmgr.dll is less than 5.0.2195.7069" negate="false" test_ref="oval:org.mitre.oval:tst:1043"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1242" version="1" class="vulnerability">
      <metadata>
        <title>sudo Symlink Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>sudo</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1993"/>
        <description>Race condition in sudo 1.3.1 up to 1.6.8p8, when the ALL pseudo-command is used after a user entry in the sudoers file, allows local users to gain privileges via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-18T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <notes>
        <note>It appears that we can't parse the vulnerable configuration condition (an ALL in the second field of a line after a line that has no ALL in the second field) with our existing regexp.</note>
      </notes>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="sudo RPM earlier than 0:1.6.7p5-1.1" negate="false" test_ref="oval:org.mitre.oval:tst:1046"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/sudoers exists" negate="false" test_ref="oval:org.mitre.oval:tst:1045"/>
          <criterion comment="/usr/bin/sudo is executable by everyone" negate="false" test_ref="oval:org.mitre.oval:tst:1044"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1241" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 6.0 Font Conversion Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0901" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0901"/>
        <description>Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-06T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Replaced all criteria. 1) Included all Win2k versions, 2) dropped explicit check for Hotfix kb885836, 3) check version of wordpad.exe rather than mswrd wpc files.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of wordpad.exe is less than 5.0.2195.6991" negate="false" test_ref="oval:org.mitre.oval:tst:1047"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1240" version="1" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898">
          <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7069" negate="false" test_ref="oval:org.mitre.oval:tst:1227"/>
          <criterion comment="the version of Mf3216.dll is less than 5.0.2195.6898" negate="false" test_ref="oval:org.mitre.oval:tst:1226"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:124" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 cachefsd Heap Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>cachefsd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0033" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0033"/>
        <description>Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code via a request with a long directory and cache name.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <modified date="2005-01-28T12:00:00.000-04:00" comment="Added patch test">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-02-01T08:29:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File cachefsd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3053"/>
          <criterion comment="Patch 108800-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3024"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains cachefsd" negate="false" test_ref="oval:org.mitre.oval:tst:3049"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File cachefsd executable">
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3048"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3047"/>
            <criterion comment="File cachefsd executable" negate="false" test_ref="oval:org.mitre.oval:tst:3046"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1239" version="2" class="vulnerability">
      <metadata>
        <title>IE5.01,SP4 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:51.888-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3828.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2359"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1237" version="1" class="vulnerability">
      <metadata>
        <title>Webproxy HTTP Request Smuggling (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00612828"/>
        <description>'An undisclosed vulnerability has been identified in Apache HTTP server versions prior to Apache 1.3.34 that may allow HTTP Request Splitting/Spoofing attacks, resulting in remote unauthorized access.'</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="VirtualvaultTS A.04.70 is installed without patch PHSS_34169 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1062"/>
          <criterion comment="Patch PHSS_34169 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2341"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.70 is installed without patch PHSS_34121 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1061"/>
          <criterion comment="Patch PHSS_34121 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1060"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.60 is installed without patch PHSS_34170 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1059"/>
          <criterion comment="Patch PHSS_34170 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1058"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.60 is installed without patch PHSS_34120 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1057"/>
          <criterion comment="Patch PHSS_34120 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1056"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.50 is installed without patch PHSS_34171 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1055"/>
          <criterion comment="Patch PHSS_34171 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1054"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.50 is installed without patch PHSS_34119 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1053"/>
          <criterion comment="Patch PHSS_34119 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1052"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed without patch PHSS_34203 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1051"/>
          <criterion comment="Patch PHSS_34203 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1050"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed without patch PHSS_34204 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1049"/>
          <criterion comment="Patch PHSS_34204 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1048"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1236" version="3" class="vulnerability">
      <metadata>
        <title>Word 2003 (wordview) Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:33.178-04:00">ACCEPTED</status_change>
            <modified date="2006-10-12T16:02:00.000-04:00" comment="Fixed filename typo in obj:1517 (referenced by tst:2648): ordview.exe to wordview.exe.">
              <contributor organization="Assuria Ltd.">Chris Wood</contributor>
            </modified>
            <status_change date="2006-10-12T16:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:29.967-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of wordview.exe is less than 11.0.6506.0" negate="false" test_ref="oval:org.mitre.oval:tst:2648"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1235" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990"/>
        <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
          </criteria>
          <criterion comment="the patch kb896727 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1129"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1231" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 DirectShow Malicious avi File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
        <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="DirectX packaged with Windows XP,SP2 has DirectShow Vulnerability">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.5.2600.0" negate="false" test_ref="oval:org.mitre.oval:tst:1064"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.2600.2749" negate="false" test_ref="oval:org.mitre.oval:tst:1063"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 8 has DirectShow Vulnerability">
          <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 9 has DirectShow Vulnerability">
          <criterion comment="DirectX 9.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1120"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1230" version="2" class="vulnerability">
      <metadata>
        <title>Windows Media Player PNG Vulnerability (v7.1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Media Player</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0025"/>
        <description>Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:15.443-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:04.887-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Media Player 7.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1066"/>
        <criterion comment="the version of wmpui.dll is less than 7.10.0.3076" negate="false" test_ref="oval:org.mitre.oval:tst:1065"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:123" version="1" class="vulnerability">
      <metadata>
        <title>IE Improper Object Tag Handling</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0809" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0809"/>
        <description>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T05:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <modified date="2004-03-04T05:00:00.000-04:00" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </modified>
            <status_change date="2004-03-25T05:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified wrt-18 - Changed value element to include pattern match">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed">
            <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
            <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          </criteria>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1264" negate="false" test_ref="oval:org.mitre.oval:tst:2918"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
            </criteria>
          </criteria>
          <criterion comment=".hta applications are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2915"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1227" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla FTP URI MIME Type Exploit Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0760" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0760"/>
        <description>Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-01-24T03:40:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 8 or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criteria operator="OR" comment="Mozilla components (any SUNWmoznav/SUNWmozmail) installed">
          <criterion comment="Mozilla (SUNWmoznav) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1070"/>
          <criterion comment="Mozilla Mail (SUNWmozmail) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1069"/>
        </criteria>
        <criterion comment="Patch 117765-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1068"/>
        <criterion comment="Patch 117767-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1067"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1226" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Improper Handling of Synthetic Events in Mozilla</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2260"/>
        <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1225" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel shmctl() Memory Swap Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0176" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0176"/>
        <description>The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL">
          <criterion comment="kernel RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1148"/>
          <criterion comment="kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1147"/>
          <criterion comment="kernel-smp RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1224" version="2" class="vulnerability">
      <metadata>
        <title>Step-by-Step Interactive Training Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Interactive Training</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1212" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1212"/>
        <description>Buffer overflow in Microsoft Step-by-Step Interactive Training (orun32.exe) allows remote attackers to execute arbitrary code via a bookmark link file (.cbo, cbl, or .cbm extension) with a long User field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-09T07:56:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-24T09:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1072 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:32.053-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Interactive Training is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1073"/>
        <criterion comment="the version of Orun32.exe is less than 3.5.0.117" negate="false" test_ref="oval:org.mitre.oval:tst:1072"/>
        <criterion comment="the patch kb898458  is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1071"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1222" version="2" class="vulnerability">
      <metadata>
        <title>MSDTC Invalid Memory Access Vulnerability (Win2K)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0034" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0034"/>
        <description>Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, aka the MSDTC Invalid Memory Access Vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-10T03:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of Msdtctm.dll is less than 2000.2.3535.0" negate="false" test_ref="oval:org.mitre.oval:tst:1074"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1221" version="1" class="vulnerability">
      <metadata>
        <title>IE6:S03 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990"/>
        <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.373" negate="false" test_ref="oval:org.mitre.oval:tst:2335"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
            </criteria>
            <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1220" version="1" class="vulnerability">
      <metadata>
        <title>WebClient Service Unchecked Buffer Remote Code Execution (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0013" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0013"/>
        <description>Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-1207.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-17T07:36:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-22T08:27:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" negate="false" test_ref="oval:org.mitre.oval:tst:2395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1216" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Server 2003 JPEG Image Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1988"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6  for Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2801"/>
        <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits">
          <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.3790.373" negate="false" test_ref="oval:org.mitre.oval:tst:2335"/>
          </criteria>
          <criteria operator="AND" comment=" a vulnerable version of mshtml.dll exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
          </criteria>
          <criteria operator="AND" comment="a vulnerable version of mshtml.dll exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:2334"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1215" version="1" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (64-bit Windows XP and Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of Gdi32.dll is less than 5.2.3790.2542" negate="false" test_ref="oval:org.mitre.oval:tst:2414"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1213" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 TAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Telephony Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-11T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
          </criteria>
          <criterion comment="the version of tapisrv.dll is less than 5.0.2195.7057" negate="false" test_ref="oval:org.mitre.oval:tst:1075"/>
          <criterion comment="the patch kb893756 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1192"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the Telephony service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1191"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1212" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.10.24)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 10.24">
          <criteria operator="AND" comment="700 Series OS Release 10.24">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.10.24" negate="false" test_ref="oval:org.mitre.oval:tst:1077"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 10.24">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.10.24" negate="false" test_ref="oval:org.mitre.oval:tst:1077"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_24394 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1076"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1210" version="1" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (WinXP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="nwwks.dll is less than 5.1.2600.2736" negate="false" test_ref="oval:org.mitre.oval:tst:1078"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:121" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft SQL Server Extended Stored Procedure Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0154"/>
        <description>Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
            </submitted>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-237 - literal string corrected">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-236 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-65 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-66 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-67 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:32:00.000-04:00" comment="modified wft-68 - Corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:33:00.000-04:00" comment="modified wft-69 - corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2977"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.608.0" negate="false" test_ref="oval:org.mitre.oval:tst:2926"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2925"/>
        <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2924"/>
        <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2923"/>
        <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2922"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:2921"/>
        <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false" test_ref="oval:org.mitre.oval:tst:2920"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1209" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 File Download Dialog Box Manipulation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2829" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2829"/>
        <description>Multiple design errors in Microsoft Internet Explorer 5.01, 5.5, and 6 allow user-assisted attackers to execute arbitrary code by (1) overlaying a malicious new window above a file download box, then (2) using a keyboard shortcut and delaying the display of the file download box until the user hits a shortcut that activates the "Run" button, aka "File Download Dialog Box Manipulation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1207" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1505 or 6.0.2800.1506">
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2365"/>
            <criterion comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2364"/>
          </criteria>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1204" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 MDAC RDS.Dataspace Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>MDAC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0003"/>
        <description>Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of msadco.dll is less than 2.81.1124.0" negate="false" test_ref="oval:org.mitre.oval:tst:1079"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1203" version="1" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1200"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1202" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 (64-bit) RPCSS DCOM Buffer Overflow (Blaster)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Distributed Component Object Model (DCOM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0715" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0715"/>
        <description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CVE-2003-0352 (Blaster/Nachi) and CVE-2003-0528.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T02:31:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows Server 2003 or Windows XP 64-Bit Edition Version 2003">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criteria operator="AND" comment="Windows XP 64-bit">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
          </criteria>
          <criterion comment="the version of rpcrt4.dll is less than 5.2.3790.76" negate="false" test_ref="oval:org.mitre.oval:tst:1080"/>
          <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="DCOM is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2913"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1201" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOEX Message Processing</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Exchange 2000 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1311"/>
        <criterion comment="cdoex.dll is less than 6.0.6617.86" negate="false" test_ref="oval:org.mitre.oval:tst:1081"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:120" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 KCMS Arbitrary File Access Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>kcms_server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0027"/>
        <description>Directory traversal vulnerability in Sun Kodak Color Management System (KCMS) library service daemon (kcms_server) allows remote attackers to read arbitrary files via the KCS_OPEN_PROFILE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-01-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File kcms_server exists" negate="false" test_ref="oval:org.mitre.oval:tst:2931"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains kcms_server" negate="false" test_ref="oval:org.mitre.oval:tst:2930"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
          <criteria operator="OR" comment="File kcms_server executable and SUID or SGID">
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2929"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2928"/>
            <criterion comment="File kcms_server executable and SUID or SGID" negate="false" test_ref="oval:org.mitre.oval:tst:2927"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12" version="1" class="vulnerability">
      <metadata>
        <title>IE v5.5,SP2 Forced Script Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0026"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4913.1100" negate="false" test_ref="oval:org.mitre.oval:tst:3122"/>
        <criterion comment="the patch q316059 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3121"/>
        <criterion comment="the patch q319282 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3120"/>
        <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
        <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
        <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
        <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
        <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1197" version="1" class="vulnerability">
      <metadata>
        <title>Firefox/Mozilla Suite Chrome Window Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2707" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2707"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address and status bar, which could be used to conduct spoofing or phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1196" version="1" class="vulnerability">
      <metadata>
        <title>URL Parsing Memory Corruption Vulnerability (IE5.01,SP3)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0554" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0554"/>
        <description>Buffer overflow in the URL processor of Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL with a long hostname, aka "URL Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-05-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-05-11T05:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-22T12:38:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3539.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1083"/>
          <criterion comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1082"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1195" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in libgd</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libgd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0941" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0941"/>
        <description>Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="AND" comment="libgd or libgd-devel RPM is earlier than 0:1.8.4-12.3.1">
          <criterion comment="libgd RPM is earlier than 0:1.8.4-12.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1085"/>
          <criterion comment="libgd-devel RPM is earlier than 0:1.8.4-12.3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1084"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1194" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Agent Security Prompt Spoofing Vulnerability (Windows XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Agent</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1214"/>
        <description>Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T03:21:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-11-17T09:54:00.000-04:00" comment="Updated obj:1000 to use new variable var:759 for path reference rather than var:200.  Now uses 'msagent' subdir of SystemRoot instead of System32.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-11-17T09:54:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:48.946-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criteria operator="OR" comment=" a vulnerable version of agentdpv exists">
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists">
              <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
                <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
                <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              </criteria>
              <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
              <criterion comment="the version of agentdpv.dll is less than 2.0.0.3423" negate="false" test_ref="oval:org.mitre.oval:tst:2425"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
              <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1241" negate="false" test_ref="oval:org.mitre.oval:tst:1476"/>
            </criteria>
            <criteria operator="AND" comment=" a vulnerable version of agentdpv exists for Windows Gold 64-bit (x64)">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of agentdpv.dll is less than 5.2.3790.1241" negate="false" test_ref="oval:org.mitre.oval:tst:1476"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb890046 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2424"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1192" version="2" class="vulnerability">
      <metadata>
        <title>.lnk File-Properties Remote Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2118"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:15.115-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="shell32.dll is less than 5.0.3900.7071" negate="false" test_ref="oval:org.mitre.oval:tst:1086"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1191" version="1" class="vulnerability">
      <metadata>
        <title>Win2K COM object Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0012"/>
        <description>Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of shell32.dll is less than 5.0.3900.7078" negate="false" test_ref="oval:org.mitre.oval:tst:1087"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1190" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Word 2002 Font Parsing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Office XPSP3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0564" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0564"/>
        <description>Stack-based buffer overflow in Microsoft Word 2000 and Word 2002, and Microsoft Works Suites 2000 through 2004, might allow remote attackers to execute arbitrary code via a .doc file with long font information.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-21T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-07-27T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wft-368 - corrected registry component to point to the key that stores the location of WinWord.exe">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Edited criteria to check for Word 2002 instead of MS Office SP3.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2005-12-20T07:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:14.812-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.00.6764.0" negate="false" test_ref="oval:org.mitre.oval:tst:1088"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1189" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Table Rebuilding Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0748" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0748"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via "an invalid and non-sensical ordering of table-related tags" that results in a negative array index.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:14.501-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Mozilla Firefox version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2443"/>
          <criterion comment="Firefox version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2442"/>
          <criterion comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1096"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.5.0.1 is installed">
          <criterion comment="Mozilla Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1095"/>
          <criterion comment="Firefox version 1.5.0.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1094"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.5 is installed and has NOT been patched with version 1.5.0.2">
          <criterion comment="Thunderbird version 1.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1093"/>
          <criterion comment="Mozilla Thunderbird version 1.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1092"/>
          <criterion comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" negate="true" test_ref="oval:org.mitre.oval:tst:1091"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="SeaMonkey version 1.0 or earlier is installed">
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1090"/>
          <criterion comment="SeaMonkey version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1089"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1186" version="1" class="vulnerability">
      <metadata>
        <title>IE .chm Directory Traversal Windows XP Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1041" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1041"/>
        <description>Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not have a .chm extension.  NOTE: this bug may overlap CVE-2004-0475.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="added the unregistered HTML Help criterion to the configuration section of the criteria">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:36:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of itss.dll is less than 5.2.3790.185" negate="false" test_ref="oval:org.mitre.oval:tst:1406"/>
          <criterion comment="the patch kb840315 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1405"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="HTML Help is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1404"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1185" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.2.3790.2549 or T2embed.dll &lt;5.2.3790.2549 (WinXP,64-bit and S03,SP1)">
          <criterion comment="the version of Fontsub.dll is less than 5.2.3790.2549" negate="false" test_ref="oval:org.mitre.oval:tst:1098"/>
          <criterion comment="the version of T2embed.dll is less than 5.2.3790.2549" negate="false" test_ref="oval:org.mitre.oval:tst:1097"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1182" version="1" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.2726" negate="false" test_ref="oval:org.mitre.oval:tst:1134"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.2726" negate="false" test_ref="oval:org.mitre.oval:tst:1133"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1180" version="1" class="vulnerability">
      <metadata>
        <title>OLE Component Input Validation Vulnerability (32-bit XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows Media Player 9</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0044" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0044"/>
        <description>The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T10:39:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T07:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.1.2600.2595" negate="false" test_ref="oval:org.mitre.oval:tst:1099"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:118" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 SMB Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0345" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0345"/>
        <description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-08T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" negate="false" test_ref="oval:org.mitre.oval:tst:2933"/>
        <criterion comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2932"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1178" version="1" class="vulnerability">
      <metadata>
        <title>IE6 DHTML Method Call Memory Corruption (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1359"/>
        <description>Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.507" negate="false" test_ref="oval:org.mitre.oval:tst:1100"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1177" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0790"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:14.323-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:04.370-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33159 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3779"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1175" version="1" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (32-bit Windows XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Gdi32.dll is less than 5.1.2600.2770" negate="false" test_ref="oval:org.mitre.oval:tst:1145"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1173" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Buffer Overflows in libXML2</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>libxml2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0989"/>
        <description>Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="libxml or libxml-devel RPM is earlier than 1:1.8.17-9.2">
          <criterion comment="libxml RPM is earlier than 1:1.8.17-9.2" negate="false" test_ref="oval:org.mitre.oval:tst:1102"/>
          <criterion comment="libxml-devel RPM is earlier than 1:1.8.17-9.2" negate="false" test_ref="oval:org.mitre.oval:tst:1101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1172" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Firefox External App Code Acceptance Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2267"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:117" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft ISA Server Cross-Site Scripting</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>ISA Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0526" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0526"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for "500 Internal Server error" or (2) 404.htm for "404 Not Found."</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="ISA Server 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2935"/>
        <criterion comment="ISA2000-KB816456-x86.exe" negate="true" test_ref="oval:org.mitre.oval:tst:2934"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1169" version="1" class="vulnerability">
      <metadata>
        <title>gzip Hard Link Attack</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0988"/>
        <description>Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false" test_ref="oval:org.mitre.oval:tst:2667"/>
        </criteria>
        <criteria comment="Configuration section" operator="OR">
          <criterion comment="/usr/bin/gunzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2665"/>
          <criterion comment="/usr/bin/gzip is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2666"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1168" version="1" class="vulnerability">
      <metadata>
        <title>Suppressed: Duplicate of OVAL3743</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word for Windows 6.0 Converter</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0571" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0571"/>
        <description>Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-05T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wrt-35 - wrt-35 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the patch kb885836 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1104"/>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of mswrd632.wpc is less than 2004.10.25.0" negate="false" test_ref="oval:org.mitre.oval:tst:1103"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Word for Windows 6.0 Converter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2421"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1167" version="2" class="vulnerability">
      <metadata>
        <title>MHT Memory Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2385" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2385"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted web page that triggers memory corruption when it is saved as a multipart HTML (.mht) file.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:14.105-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:03.872-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1165" version="2" class="vulnerability">
      <metadata>
        <title>Outlook 2002 TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:25:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-05-31T01:11:00.000-04:00" comment="modified wft-735 - Fixed version operator--was \&quot;greater than\&quot; by mistake.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-05-31T09:44:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:13.832-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1106"/>
        <criterion comment="the version of msmapi32.dll is less than 10.0.6772.0" negate="false" test_ref="oval:org.mitre.oval:tst:1105"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1163" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0516" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0516"/>
        <description>Unspecified vulnerability in the kernel processing in Solaris 10 64 bit platform, when running in 64-bit mode, allows local users to cause a denial of service (system panic) via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:13.671-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:03.356-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Solaris 10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3680"/>
        <criterion comment="x86" negate="false" test_ref="oval:org.mitre.oval:tst:3912"/>
        <criterion comment="Patch 118844-14 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3960"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1161" version="2" class="vulnerability">
      <metadata>
        <title>Exchange Server 2003,SP1 when running Outlook Web Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1193"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:13.425-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:02.839-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2003,SP1 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1108"/>
        <criterion comment="mdbmsg.dll is less than 6.5.7233.69" negate="false" test_ref="oval:org.mitre.oval:tst:1107"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1160" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1323" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1323"/>
        <description>Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:52:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:13.239-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:02.270-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="Solaris 8 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:3437"/>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101426 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119449-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3644"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101426 criteria." negate="false">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3172"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3237"/>
          <criterion comment="Patch 119450-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3771"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1159" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 COM Structured Storage Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0047" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0047"/>
        <description>Windows 2000, XP, and Server 2003 does not properly "validate the use of memory regions" for COM structured storage files, which allows attackers to execute arbitrary code, aka the "COM Structured Storage Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-02-18T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of ole32.dll is less than 5.0.2195.7021" negate="false" test_ref="oval:org.mitre.oval:tst:1109"/>
        <criterion comment="the patch KB873333 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1158" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2000 Remote Code Execution via Malformed File Format</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0028" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0028"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-15T10:53:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-15T07:17:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:1110) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:12.988-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8938" negate="false" test_ref="oval:org.mitre.oval:tst:1110"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1155" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 (64-bit) DDS Library Shape Control Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2127" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2127"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the (1) DDS Library Shape Control (Msdds.dll) COM object, and other objects including (2) Blnmgrps.dll, (3) Ciodm.dll, (4) Comsvcs.dll, (5) Danim.dll, (6) Htmlmarq.ocx, (7) Mdt2dd.dll (as demonstrated using a heap corruption attack with uninitialized memory), (8) Mdt2qd.dll, (9) Mpg4ds32.ax, (10) Msadds32.ax, (11) Msb1esen.dll, (12) Msb1fren.dll, (13) Msb1geen.dll, (14) Msdtctm.dll, (15) Mshtml.dll, (16) Msoeacct.dll, (17) Msosvfbr.dll, (18) Mswcrun.dll, (19) Netshell.dll, (20) Ole2disp.dll, (21) Outllib.dll, (22) Psisdecd.dll, (23) Qdvd.dll, (24) Repodbc.dll, (25) Shdocvw.dll, (26) Shell32.dll, (27) Soa.dll, (28) Srchui.dll, (29) Stobject.dll, (30) Vdt70.dll, (31) Vmhelper.dll, and (32) Wbemads.dll, aka a variant of the "COM Object Instantiation Memory Corruption vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="mshtml.dll is less than 6.0.3790.2541" negate="false" test_ref="oval:org.mitre.oval:tst:1114"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1154" version="1" class="vulnerability">
      <metadata>
        <title>bzip2 Arbitrary File Permission Modification Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>bzip2</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0953" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0953"/>
        <description>Race condition in bzip2 1.0.2 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by bzip2 after the decompression is complete.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false" test_ref="oval:org.mitre.oval:tst:2386"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/bzip2 is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2385"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1152" version="1" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (32-bit Windows XP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criteria operator="OR" comment="version of Gdi32.dll is less than 5.1.2600.1755 OR the version of Mf3216.dll is less than 5.1.2600.1331">
          <criterion comment="the version of Gdi32.dll is less than 5.1.2600.1755" negate="false" test_ref="oval:org.mitre.oval:tst:1116"/>
          <criterion comment="the version of Mf3216.dll is less than 5.1.2600.1331" negate="false" test_ref="oval:org.mitre.oval:tst:1115"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1151" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd Remote Unauthorized Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>remshd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN or InternetSrvcs.INET-ENG-A-MAN (B.11.11) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1119"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1118"/>
        </criteria>
        <criterion comment="Patch PHNE_33791 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1117"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1150" version="1" class="vulnerability">
      <metadata>
        <title>Crash on "zero-width non-joiner" Sequence</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2702" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2702"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:115" version="2">
      <metadata>
        <title>Hyperlink Object Function Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference ref_id="CVE-2006-3438" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3438" source="CVE"/>
        <description>Unspecified vulnerability in Microsoft Hyperlink Object Library (hlink.dll), possibly a buffer overflow, allows user-assisted attackers to execute arbitrary code via crafted hyperlinks that are not properly handled when hlink.dll "uses a file containing a malformed function," aka "Hyperlink Object Function Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:26.729-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:19.875-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP1" operator="AND">
          <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.560" test_ref="oval:org.mitre.oval:tst:114"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Hlink.dll is less than 5.2.3790.2748" test_ref="oval:org.mitre.oval:tst:180"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1149" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 DirectShow Malicious avi File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2128"/>
        <description>QUARTZ.DLL in Microsoft Windows Media Player 9 allows remote attackers to write a null byte to arbitrary memory via an AVI file with a crafted strn element with a modified length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="DirectX packaged with Windows Server 2003,SP1 has DirectShow Vulnerability">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="a Win2K/XP/2003 service pack is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2845"/>
          <criterion comment="the version of Quartz.dll is greater than or equal to 6.5.3790.0" negate="false" test_ref="oval:org.mitre.oval:tst:1123"/>
          <criterion comment="the version of Quartz.dll is less than 6.5.3790.2519" negate="false" test_ref="oval:org.mitre.oval:tst:1122"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 8 has DirectShow Vulnerability">
          <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
        <criteria operator="AND" comment="Standalone DirectX 9 has DirectShow Vulnerability">
          <criterion comment="DirectX 9.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1120"/>
          <criterion comment="the version of Quartz.dll is less than 6.3.1.889" negate="false" test_ref="oval:org.mitre.oval:tst:1121"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1148" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Installed XP,SP2 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2668" negate="false" test_ref="oval:org.mitre.oval:tst:1150"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1147" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1124"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1146" version="2" class="vulnerability">
      <metadata>
        <title>FTP Download Destination Tampering Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2126" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2126"/>
        <description>The FTP client in Windows XP SP1 and Server 2003, and Internet Explorer 6 SP1 on Windows 2000 SP4, when "Enable Folder View for FTP Sites" is enabled and the user manually initiates a file transfer, allows user-assisted, remote FTP servers to overwrite files in arbitrary locations via crafted filenames.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-31T12:00:00.000-04:00" comment="removed an incorrect leading ^ from the value entity of ste:2402">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-31T00:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:12.684-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2569"/>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="msieftp.dll is less than 5.50.4956.500" negate="false" test_ref="oval:org.mitre.oval:tst:1125"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1145" version="1" class="vulnerability">
      <metadata>
        <title>ISA Server Poison Cache Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>ISA Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1215" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1215"/>
        <description>Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-06-29T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wft-81 - Removed extra trailing \\ on registry component.">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="ISA Server 2000 SP2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2611"/>
        <criterion comment="the version of w3proxy.exe is less than 3.0.1200.430" negate="false" test_ref="oval:org.mitre.oval:tst:2610"/>
        <criterion comment="the patch KB899753 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2609"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1144" version="1" class="vulnerability">
      <metadata>
        <title>IE6 HTML Tag Memory Corruption (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1188" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1188"/>
        <description>Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2666" negate="false" test_ref="oval:org.mitre.oval:tst:1126"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1143" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1142" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Unknown Vector SMB Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>SMB (Server Message Block)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1206" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1206"/>
        <description>Buffer overflow in the Server Message Block (SMB) functionality for Microsoft Windows 2000, XP SP1 and SP2, and Server 2003 and SP1 allows remote attackers to execute arbitrary code via unknown vectors, aka the "Server Message Block Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment=" a vulnerable version of srv.sys exists">
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of srv.sys exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of srv.sys is less than 5.1.2600.1683" negate="false" test_ref="oval:org.mitre.oval:tst:1128"/>
          </criteria>
          <criteria operator="AND" comment="32-bit version of windows with SP2 is installed and vulnerable version of srv.sys exists">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the version of srv.sys is less than 5.1.2600.2673" negate="false" test_ref="oval:org.mitre.oval:tst:1127"/>
          </criteria>
          <criteria operator="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of srv.sys exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of srv.sys is less than 5.2.3790.2437" negate="false" test_ref="oval:org.mitre.oval:tst:2745"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB896422 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2743"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1140" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 JPEG Image Rendering Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1988" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1988"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to execute arbitrary code via a web site or an HTML e-mail containing a crafted JPEG image that causes memory corruption, aka "JPEG Image Rendering Memory Corruption Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criteria operator="OR" comment="the version of mshtml.dll is less than 6.0.2800.1515 or 6.0.2800.1516">
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" negate="false" test_ref="oval:org.mitre.oval:tst:2418"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" negate="false" test_ref="oval:org.mitre.oval:tst:2417"/>
        </criteria>
        <criterion comment="the patch kb896727 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1129"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:114" version="1" class="vulnerability">
      <metadata>
        <title>String Format Vulnerability in Solaris 7 snmpdx</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>snmpdx</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0796"/>
        <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File snmpdx exists" negate="false" test_ref="oval:org.mitre.oval:tst:3126"/>
          <criterion comment="Patch 107709-19 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2994"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpdx running" negate="false" test_ref="oval:org.mitre.oval:tst:3124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1139" version="1" class="vulnerability">
      <metadata>
        <title>Telnet Client Information Disclosure Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>telnet</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0488" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0488"/>
        <description>Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="telnet RPM earlier than 1:0.17-20.EL3.3" negate="false" test_ref="oval:org.mitre.oval:tst:1131"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/telnet is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:1130"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1137" version="2" class="vulnerability">
      <metadata>
        <title>SMB Driver Elevation of Privilege Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2373" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2373"/>
        <description>The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method flag and an arbitrary address, possibly for kernel memory, aka the "SMB Driver Elevation of Privilege Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:12.522-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:01.650-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mrxsmb.sys is less than 5.2.3790.2697" negate="false" test_ref="oval:org.mitre.oval:tst:1132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1136" version="1" class="vulnerability">
      <metadata>
        <title>Distributed TIP Request Validation Process Permits Denial of Service (Server 2003,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1980" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1980"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after an error occurs, aka the "Distributed TIP Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.2.3790.2492">
          <criterion comment="the version of ole32.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2539"/>
          <criterion comment="the version of rpcss.dll is less than 5.2.3790.2492" negate="false" test_ref="oval:org.mitre.oval:tst:2538"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1135" version="2" class="vulnerability">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1303" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1303"/>
        <description>Multiple unspecified vulnerabilities in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allow remote attackers to execute arbitrary code by instantiating certain COM objects from Wmm2fxa.dll as ActiveX controls including (1) DXImageTransform.Microsoft.MMSpecialEffect1Input, (2) DXImageTransform.Microsoft.MMSpecialEffect1Input.1, (3) DXImageTransform.Microsoft.MMSpecialEffect2Inputs, (4) DXImageTransform.Microsoft.MMSpecialEffect2Inputs.1, (5) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input, and (6) DXImageTransform.Microsoft.MMSpecialEffectInplace1Input.1, which causes memory corruption during garbage collection.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:12.372-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:01.169-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1134" version="1" class="vulnerability">
      <metadata>
        <title>TIP Request Validation Process Permits Denial of Service (XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>TIP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1979" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1979"/>
        <description>Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction Internet Protocol (TIP) functionality.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
          <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.2726">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.2726" negate="false" test_ref="oval:org.mitre.oval:tst:1134"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.2726" negate="false" test_ref="oval:org.mitre.oval:tst:1133"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1133" version="1" class="vulnerability">
      <metadata>
        <title>Scob and Toofer Internet Explorer v6.0,SP1 Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0549" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0549"/>
        <description>The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the location to execute code such as Javascript, as demonstrated using (1) delayed HTTP redirect operations, and an HTTP response with a Location: header containing a "URL:" prepended to a "ms-its" protocol URI, or (2) modifying the location attribute of the window, as exploited by the Download.ject (aka Scob aka Toofer) using the ADODB.Stream object.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-08-02T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T11:01:00.000-04:00" comment="modified wft-267 - Changed comment to match test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1458" negate="false" test_ref="oval:org.mitre.oval:tst:2765"/>
          <criterion comment="the patch kb832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2802"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1132" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP Telnet Environment Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Services for UNIX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1205" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1205"/>
        <description>The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of telnet.exe exists">
          <criteria operator="OR" comment="for specific Windows configurations a vulnerable version of telnet.exe exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of telnet.exe is less than 5.1.2600.1684" negate="false" test_ref="oval:org.mitre.oval:tst:1135"/>
          </criteria>
          <criteria operator="AND" comment="32-bit version of windows with SP2 is installed and vulnerable version of telnet.exe exists">
            <criterion comment="the version of telnet.exe is less than 5.1.2600.1684" negate="false" test_ref="oval:org.mitre.oval:tst:1135"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
          </criteria>
          <criteria operator="AND" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of telnet.exe exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of telnet.exe is less than 5.2.3790.2442" negate="false" test_ref="oval:org.mitre.oval:tst:2503"/>
          </criteria>
        </criteria>
        <criterion comment="the patch KB896428 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2502"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1130" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflow in CDOSYS Message Processing (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1987"/>
        <description>Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="cdosys.dll is less than 6.5.6749.0" negate="false" test_ref="oval:org.mitre.oval:tst:1136"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:113" version="1" class="vulnerability">
      <metadata>
        <title>X Display Manager Control Protocol Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0548" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0548"/>
        <description>The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gdm version is less than 2.4.1.3-5.1" negate="false" test_ref="oval:org.mitre.oval:tst:2936"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1127" version="1" class="vulnerability">
      <metadata>
        <title>Buffer Overflows in uucp</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>uucp</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1359" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1359"/>
        <description>Multiple buffer overflows in uucp for Sun Solaris 2.6, 7, 8, and 9 allow local users to execute arbitrary code as the uucp user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-04-13T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-04-20T04:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-05-11T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-08-22T04:00:00.000-04:00" comment="Product set to uucp; was mistakenly .NET framework">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-08-25T10:03:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Solaris 7,8,or 9 installed">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
        </criteria>
        <criterion comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1140"/>
        <criterion comment="Patch 106952-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1139"/>
        <criterion comment="Patch 111570-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1138"/>
        <criterion comment="Patch 113322-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1137"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1126" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Embedded Web Font Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0010"/>
        <description>Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type (EOT) web font that triggers the overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criteria operator="OR" comment="Fontsub.dll &lt; 5.2.3790.426 or T2embed.dll &lt;5.2.3790.426 (S03-Gold)">
          <criterion comment="the version of Fontsub.dll is less than 5.2.3790.426" negate="false" test_ref="oval:org.mitre.oval:tst:1142"/>
          <criterion comment="the version of T2embed.dll is less than 5.2.3790.426" negate="false" test_ref="oval:org.mitre.oval:tst:1141"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1125" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Color Management Module Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Color Management Module</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1219"/>
        <description>Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-02T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-08-03T11:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of mscms.dll is less than 5.2.3790.359" negate="false" test_ref="oval:org.mitre.oval:tst:1143"/>
        <criterion comment="the patch KB901214 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2697"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1124" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Fetchmail Buffer Overflow via Long UIDL Responses</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>fetchmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2335"/>
        <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
          <criterion comment="fetchmail RPM earlier than 0:6.2.5-6.el4.2" negate="false" test_ref="oval:org.mitre.oval:tst:1144"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/fetchmail is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:1261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1122" version="1" class="vulnerability">
      <metadata>
        <title>Linux Kernel elf_core_dump() Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1263"/>
        <description>The elf_core_dump function in binfmt_elf.c for Linux kernel 2.x.x to 2.2.27-rc2, 2.4.x to 2.4.31-pre1, and 2.6.x to 2.6.12-rc4 allows local users to execute arbitrary code via an ELF binary that, in certain conditions involving the create_elf_tables function, causes a negative length argument to pass a signed integer comparison, leading to a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL">
          <criterion comment="kernel RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1148"/>
          <criterion comment="kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1147"/>
          <criterion comment="kernel-smp RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1121" version="1" class="vulnerability">
      <metadata>
        <title>EMF Rendering Denial of Service Vulnerability (32-bit Windows XP,SP2)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0803"/>
        <description>The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka "Enhanced Metafile Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of Gdi32.dll is less than 5.1.2600.2770" negate="false" test_ref="oval:org.mitre.oval:tst:1145"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:112" version="1" class="vulnerability">
      <metadata>
        <title>GDM Examine Errors Symlink Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>GDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0547" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0547"/>
        <description>GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-09-04T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="gdm version is less than 2.4.1.3-5.1" negate="false" test_ref="oval:org.mitre.oval:tst:2936"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1118" version="1" class="vulnerability">
      <metadata>
        <title>MS Windows RPC DCOM DoS-based Privilege Escalation Vulnerability (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0605" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0605"/>
        <description>The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface that cause a NULL pointer to be passed to the PerformScmStage function.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-01-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2005-01-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-17T12:00:00.000-04:00" comment="modified cmp-1106 - Replaced the test that checks for the service pack level, instead of checking for sp4 or ealier (did not check for GOLD edition) it is now negating the test that checks for sp5 for later.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-06-22T12:35:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp4 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 5 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2790"/>
        </criteria>
        <criterion comment="the version of rpcrt4.dll is less than 5.0.2195.6802" negate="false" test_ref="oval:org.mitre.oval:tst:2914"/>
        <criterion comment="the patch kb824146 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:3082"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1117" version="1" class="vulnerability">
      <metadata>
        <title>mlock Memory Page Tracking Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Linux kernel</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0491"/>
        <description>The linux-2.4.21-mlock.patch in Red Hat Enterprise Linux 3 does not properly maintain the mlock page count when one process unlocks pages that belong to another process, which allows local users to mlock more memory than specified by the rlimit.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criteria operator="OR" comment="kernel, kernel-smp or kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL">
          <criterion comment="kernel RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1148"/>
          <criterion comment="kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1147"/>
          <criterion comment="kernel-smp RPM earlier than 0:2.4.21-32.0.1.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1146"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1116" version="1" class="vulnerability">
      <metadata>
        <title>.lnk File-Properties Remote Code Execution Vulnerability (Windows XP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2118" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2118"/>
        <description>Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views the file's properties using Windows Explorer, a different vulnerability than CVE-2005-2122.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="shell32.dll is less than 6.0.2800.1751" negate="false" test_ref="oval:org.mitre.oval:tst:1149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1115" version="2" class="vulnerability">
      <metadata>
        <title>IE6,SP2 PNG Image Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1211" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1211"/>
        <description>Buffer overflow in the PNG image rendering component of Microsoft Internet Explorer allows remote attackers to execute arbitrary code via a crafted PNG file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T02:13:00.000-04:00">DRAFT</status_change>
            <modified date="2005-06-24T12:00:00.000-04:00" comment="added description">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-17T04:13:00.000-04:00" comment="Fixed registry_object obj:1557 by moving PNGFilter.CoPNGFilter from name to end of key, and setting xsi:nil to true on name.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-17T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:57:50.374-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2668" negate="false" test_ref="oval:org.mitre.oval:tst:1150"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="PNG image rendering enabled in Internet Explorer" negate="false" test_ref="oval:org.mitre.oval:tst:2749"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1114" version="1" class="vulnerability">
      <metadata>
        <title>IE AbusiveParent Vulnerability (32-bit Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1319" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1319"/>
        <description>The DHTML Edit Control (dhtmled.ocx) allows remote attackers to inject arbitrary web script into other domains by setting a name for a window, opening a child page whose target is the window with the given name, then injecting the script from the parent into the child using execScript, as demonstrated by "AbusiveParent" in Internet Explorer 6.0.2900.2180.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2005-02-11T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-03-02T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Microsoft Windows Server 2003 32-Bit Edition">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="the version of dhtmled.ocx is less than 6.1.0.9231" negate="false" test_ref="oval:org.mitre.oval:tst:1152"/>
        <criterion comment="the patch kb891781 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1151"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1112" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:12.194-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:00.625-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.04" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_33427 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1110" version="1" class="vulnerability">
      <metadata>
        <title>Kerberos V5 Null Pointer DoS Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Solaris Enterprise Authentication Mechanism (SEAM)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0058"/>
        <description>MIT Kerberos V5 Key Distribution Center (KDC) before 1.2.5 allows remote authenticated attackers to cause a denial of service (crash) on KDCs within the same realm via a certain protocol request that causes a null dereference.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 and Solaris Enterprise Authentication Mechanism OR Solaris 8 or 9 installed">
            <criteria operator="AND" comment="Solaris 7 AND Solaris Enterprise Authentication Mechanism installed">
              <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
              <criteria operator="OR" comment="Solaris Enterprise Authentication Mechanism (ANY SUNWkr5sl/SUNWkr5sv/SUNWkrgdo/SUNWkrggl)">
                <criterion comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1161"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1160"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1159"/>
                <criterion comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1158"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="Solaris 8 or 9 installed">
              <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
              <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            </criteria>
          </criteria>
          <criterion comment="Patch 112536-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1157"/>
          <criterion comment="Patch 112908-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1156"/>
          <criterion comment="Patch 112237-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1155"/>
          <criterion comment="Patch 112390-07 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1154"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/etc/krb5/krb5.conf is configured with a kerberos domain" negate="false" test_ref="oval:org.mitre.oval:tst:1153"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:111" version="1" class="vulnerability">
      <metadata>
        <title>Ximian Evolution MIME-encoded Image Buffer Overflow</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ximian Evolution</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0130" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0130"/>
        <description>The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly escape HTML characters, which allows remote attackers inject arbitrary data and HTML via a MIME Content-ID header in a MIME-encoded image.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="evolution version is less than 1.2.2-5" negate="false" test_ref="oval:org.mitre.oval:tst:2939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1107" version="1" class="vulnerability">
      <metadata>
        <title>gzip zgrep Sanitation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>gzip</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0758"/>
        <description>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="gzip RPM earlier than 0:1.3.3-12rhel3" negate="false" test_ref="oval:org.mitre.oval:tst:2667"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/zgrep is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:1162"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1106" version="1" class="vulnerability">
      <metadata>
        <title>CSNW Remote Buffer Overflow via Network Messages (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>NetWare</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1985" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1985"/>
        <description>The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="nwwks.dll is less than 5.1.2600.1727" negate="false" test_ref="oval:org.mitre.oval:tst:1163"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1105" version="1" class="vulnerability">
      <metadata>
        <title>GDI+ JPEG Parsing Engine Buffer Overflow (Server 2003)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>GDI+</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0200" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0200"/>
        <description>Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-09-20T03:22:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-09-22T02:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-10-06T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-10-20T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-20T07:05:00.000-04:00" comment="Changed criteria to filter out 32-bit XP consideration.  wft-493 will always be positive on 32-bit machines.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="64-bit XP or Server 2003 is installed">
          <criteria operator="AND" comment="64-bit XP is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
          </criteria>
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        </criteria>
        <criterion comment="the version of sxs.dll is less than 5.2.3790.121" negate="false" test_ref="oval:org.mitre.oval:tst:1164"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1104" version="1" class="vulnerability">
      <metadata>
        <title>DirectX 9 DirectShow Malicious MIDI File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0346"/>
        <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-31T06:03:00.000-04:00" comment="Updated reference to CVE-2003-0346.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="DirectX 9.0 or 9.0a installed.">
          <criterion comment="DirectX 9.0-gold Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1166"/>
          <criterion comment="DirectX 9.0a Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1165"/>
        </criteria>
        <criterion comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1172"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1101" version="1" class="vulnerability">
      <metadata>
        <title>WinXP,SP1 (64-bit) HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        </criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2577" negate="false" test_ref="oval:org.mitre.oval:tst:1167"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:11" version="1" class="vulnerability">
      <metadata>
        <title>String Format Vulnerability in Solaris 8 snmpdx</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>snmpdx</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0796" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0796"/>
        <description>Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File snmpdx exists" negate="false" test_ref="oval:org.mitre.oval:tst:3126"/>
          <criterion comment="Patch 108869-16 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3125"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpdx running" negate="false" test_ref="oval:org.mitre.oval:tst:3124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1099" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 9 CDE ToolTalk Database Null Write Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 9</platform>
          <product>CDE</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0677" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0677"/>
        <description>CDE ToolTalk database server (ttdbserver) allows remote attackers to overwrite arbitrary memory locations with a zero, and possibly gain privileges, via a file descriptor argument in an AUTH_UNIX procedure call, which is used as a table index by the _TT_ISCLOSE procedure.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified sat-6 - Changed test to pattern match and added check for 64bit version">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified sat-6 - Changed regular expression test to properly check for 64bit package">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </modified>
            <status_change date="2005-01-24T02:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1169"/>
          <criterion comment="Patch 112808-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1168"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="inetd.conf contains rpc.ttdbserverd" negate="false" test_ref="oval:org.mitre.oval:tst:3103"/>
          <criterion comment="inetd running" negate="false" test_ref="oval:org.mitre.oval:tst:3135"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1098" version="1" class="vulnerability">
      <metadata>
        <title>usermod Recursive Ownership Error (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00614838"/>
        <description>A security flaw in some versions of the HP-UX usermod command can result in recursively changing the ownership of all directories and files under a user's home directory.  Specifically, executing	# usermod -d &lt;old home dir> -u &lt;new gid> -m &lt;username> or	# usermod -d &lt;old home dir> -u &lt;new or old gid> -m &lt;username> incorrectly changes ownership recursively to &lt;username>.  If the home directory is '/', this action will render the system inoperable.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1097" version="1" class="vulnerability">
      <metadata>
        <title>Win2K/XP,SP1 HTTPS Proxy Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2830" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2830"/>
        <description>Microsoft Internet Explorer 5.01, 5.5, and 6, when using an HTTPS proxy server that requires Basic Authentication, sends URLs in cleartext, which allows remote attackers to obtain sensitive information, aka "HTTPS Proxy Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-12-13T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-16T01:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Win2K or XP,SP1 is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criteria operator="AND" comment="Windows XP 32-bit SP1 is installed">
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.2800.1528" negate="false" test_ref="oval:org.mitre.oval:tst:2390"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1096" version="1" class="vulnerability">
      <metadata>
        <title>IE Web Page Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0339" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0339"/>
        <description>Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Internet Explorer 5.5 Installed">
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1466"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1465"/>
          <criterion comment="Internet Explorer 5.5 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1464"/>
        </criteria>
        <criterion comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" negate="false" test_ref="oval:org.mitre.oval:tst:1171"/>
        <criterion comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" negate="false" test_ref="oval:org.mitre.oval:tst:1170"/>
        <criterion comment="Patch Q295106 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1461"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1095" version="1" class="vulnerability">
      <metadata>
        <title>DirectX 8 DirectShow Malicious MIDI File Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>DirectX</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0346" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0346"/>
        <description>Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-31T05:11:00.000-04:00" comment="Updated reference to CVE-2003-0346.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="DirectX 8.x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1173"/>
        <criterion comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1172"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1094" version="1" class="vulnerability">
      <metadata>
        <title>IE plugin.ocx Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0233"/>
        <description>Heap-based buffer overflow in plugin.ocx for Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code via the Load() method, a different vulnerability than CVE-2003-0115.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-30T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T11:10:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Internet Explorer 5.5 Service Pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3123"/>
        <criterion comment="the version of mshtml.dll is less than 5.50.4926.2500" negate="false" test_ref="oval:org.mitre.oval:tst:1454"/>
        <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
        <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
        <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
        <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
        <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
        <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1093" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 SSL PCT Handshake Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Private Communications Transport (PCT)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0719"/>
        <description>Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of schannel.dll is less than 5.2.3790.132" negate="false" test_ref="oval:org.mitre.oval:tst:1509"/>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SSL is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1508"/>
          <criterion comment="PCT support is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1503"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1091" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 IE Mismatched Document Object Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1790" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1790"/>
        <description>Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched Document Object Model Objects Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <modified date="2005-12-14T12:00:00.000-04:00" comment="Updated with newly available information.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1177"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.449" negate="false" test_ref="oval:org.mitre.oval:tst:1176"/>
        <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
        <criteria operator="OR" comment="Server 2003 IE Enhanced Security is installed and set.">
          <criterion comment="Server 2003 IE Enhanced Security (Administror) is installed and set." negate="false" test_ref="oval:org.mitre.oval:tst:1175"/>
          <criterion comment="Server 2003 IE Enhanced Security (User) is installed and set." negate="false" test_ref="oval:org.mitre.oval:tst:1174"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:109" version="1" class="vulnerability">
      <metadata>
        <title>Windows ntdll.dll Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0109" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0109"/>
        <description>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-10-10T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (sp3 or earlier) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of ntdll.dll is less than 5.0.2195.6685" negate="false" test_ref="oval:org.mitre.oval:tst:2938"/>
        <criterion comment="the patch q815021 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2937"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1089" version="1" class="vulnerability">
      <metadata>
        <title>XMLHttpRequest Header Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2703" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2703"/>
        <description>Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-11T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-12T10:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.10 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2535"/>
          <criterion comment="Mozilla Suite version 1.7.10 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2534"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.6 or earlier is installed">
          <criterion comment="Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2533"/>
          <criterion comment="Mozilla Firefox version 1.0.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1088" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express 5.5,SP2 News Reading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1213" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1213"/>
        <description>Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 5.5 SP2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1514"/>
        <criterion comment="the version of inetcomm.dll is less than 5.50.4952.2800" negate="false" test_ref="oval:org.mitre.oval:tst:1178"/>
        <criterion comment="Patch KB897715 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2853"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1087" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Garbage-collection Hazard Audit</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1742" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1742"/>
        <description>The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:11.874-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1086" version="1" class="vulnerability">
      <metadata>
        <title>PostgreSQL tsearch2 "internal" Functions Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>postgresql</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1410" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1410"/>
        <description>The tsearch2 module in PostgreSQL 7.4 through 8.0.x declares the (1) dex_init, (2) snb_en_init, (3) snb_ru_init, (4) spell_init, and (5) syn_init functions as "internal" even when they do not take an internal argument, which allows attackers to cause a denial of service (application crash) and possibly have other impacts via SQL commands that call other functions that accept internal arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-27T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-06-29T06:49:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="rh-postgresql-contrib rpm is earlier than 0:7.3.10-1" negate="false" test_ref="oval:org.mitre.oval:tst:1180"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="postmaster (the PostgreSQL master daemon) is running" negate="false" test_ref="oval:org.mitre.oval:tst:2432"/>
          <criterion comment="/usr/lib/pgsql/tsearch.so (PostgreSQL's tsearch module) exists as a regular file" negate="false" test_ref="oval:org.mitre.oval:tst:1179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1082" version="1" class="vulnerability">
      <metadata>
        <title>Exchange 2000 Server TNEF Decoding Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0002" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0002"/>
        <description>Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:56:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:21:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-01T09:08:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of Mapi32.dll is greater than or equal 6.0.6603.0 (Exchange 2000 Server,SP3 is installed)" negate="false" test_ref="oval:org.mitre.oval:tst:1182"/>
        <criterion comment="the version of Mapi32.dll is less than 6.0.6617.47" negate="false" test_ref="oval:org.mitre.oval:tst:1181"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1081" version="1" class="vulnerability">
      <metadata>
        <title>gzip Argument Sanitation Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>zgrep</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0758" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0758"/>
        <description>zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-07-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-07-27T10:36:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" negate="false" test_ref="oval:org.mitre.oval:tst:2386"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/bzgrep is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1183"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:108" version="1" class="vulnerability">
      <metadata>
        <title>Ximian Evolution User Agent Multiple uuencoding Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ximian Evolution</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0129" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0129"/>
        <description>Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumption) via a mail message that is uuencoded multiple times.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="evolution version is less than 1.2.2-5" negate="false" test_ref="oval:org.mitre.oval:tst:2939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1079" version="1" class="vulnerability">
      <metadata>
        <title>MS CIFS Spoofed Browse Frame Request Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetBIOS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-1079" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1079"/>
        <description>Interactions between the CIFS Browser Protocol and NetBIOS as implemented in Microsoft Windows 95, 98, NT, and 2000 allow remote attackers to modify dynamic NetBIOS name cache entries via a spoofed Browse Frame Request in a unicast or UDP broadcast datagram.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-398 - corrected regular expression on key. needed to escape all back slashes">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T01:23:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows 95, 98, NT or 2000 is installed">
            <criterion comment="Windows 95 or 98 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1186"/>
            <criteria operator="OR" comment="Windows NT or 2000 Installed">
              <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
              <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="TCP/IP NetBIOS not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:1185"/>
          <criterion comment="WINS Client binding not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:1184"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1078" version="2" class="vulnerability">
      <metadata>
        <title>Exception Handling Memory Corruption Vulnerability (S03,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-2218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2218"/>
        <description>Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a variant of CVE-2006-1992.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:11.683-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:00.155-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2706" negate="false" test_ref="oval:org.mitre.oval:tst:1187"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1077" version="1" class="vulnerability">
      <metadata>
        <title>MS SQL Server 2000 Resolution Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0649" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0649"/>
        <description>Multiple buffer overflows in SQL Server 2000 Resolution Service allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-426 - Added space to registry key. used to say &quot;AppPaths&quot; I changed it to &quot;App Paths&quot;">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-426 - wft-426 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-427 - wft-427 correct literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 installed" negate="false" test_ref="oval:org.mitre.oval:tst:2591"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.636.0" negate="false" test_ref="oval:org.mitre.oval:tst:1189"/>
        <criterion comment="the version of ssnetlib.dll is less than 2000.80.636.0" negate="false" test_ref="oval:org.mitre.oval:tst:1188"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1076" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT/2000 ASN.1 Library Double-free Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0123"/>
        <description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows NT or 2000 is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        </criteria>
        <criterion comment="the version of msasn1.dll is less than 5.0.2195.6905" negate="false" test_ref="oval:org.mitre.oval:tst:1190"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1075" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP TAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Telephony Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-11T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criteria operator="OR" comment=" a vulnerable version of tapisrv.dll exists">
            <criteria operator="AND" comment="32-bit version of windows with SP1 or earlier is installed and vulnerable version of tapisrv.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
              <criterion comment="the version of tapisrv.dll is less than 5.1.2600.1715" negate="false" test_ref="oval:org.mitre.oval:tst:1195"/>
            </criteria>
            <criteria operator="AND" comment="32-bit version of windows with SP2 is installed and vulnerable version of tapisrv.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
              <criterion comment="the version of tapisrv.dll is less than 5.1.2600.2716" negate="false" test_ref="oval:org.mitre.oval:tst:1194"/>
            </criteria>
            <criteria operator="AND" comment=" for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of tapisrv.dll exists">
              <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false" test_ref="oval:org.mitre.oval:tst:1193"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb893756 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1192"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the Telephony service is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1191"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1074" version="1" class="vulnerability">
      <metadata>
        <title>Perl Format String Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 10</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3962" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3962"/>
        <description>Integer overflow in the format string functionality (Perl_sv_vcatpvfn) in Perl 5.9.2 and 5.8.6 Perl allows attackers to overwrite arbitrary memory and possibly execute arbitrary code via format string specifiers with large values, which causes an integer wrap and leads to a buffer overflow, as demonstrated using format string vulnerabilities in Perl applications.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-02T02:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 102192 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 119985-02 or later installed (SPARC-10)" negate="true" test_ref="oval:org.mitre.oval:tst:1197"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 102192 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 122082-01 or later installed (x86-10)" negate="true" test_ref="oval:org.mitre.oval:tst:1196"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1073" version="1" class="vulnerability">
      <metadata>
        <title>RHE4 Firefox External App Code Acceptance Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 4</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2267"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" negate="false" test_ref="oval:org.mitre.oval:tst:2651"/>
          <criterion comment="Red Hat Enterprise 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2652"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/mozilla is executable" negate="false" test_ref="oval:org.mitre.oval:tst:2650"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1072" version="1" class="vulnerability">
      <metadata>
        <title>DCOM RPC Object Identity Windows XP Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0124"/>
        <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:34:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of comsvcs.dll is less than 2001.12.4414.53" negate="false" test_ref="oval:org.mitre.oval:tst:1198"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1071" version="1" class="vulnerability">
      <metadata>
        <title>MSDTC Unchecked Buffer Permits Remote Code Execution or Privilege Elevation (WinXP,SP1)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>MSDTC</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2119" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2119"/>
        <description>The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-10-12T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-10-19T05:46:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
        </criteria>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criteria operator="OR" comment="Either ole32.dll or rpcss.dll has a version less than 5.1.2600.1720">
          <criterion comment="the version of ole32.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1200"/>
          <criterion comment="the version of rpcss.dll is less than 5.1.2600.1720" negate="false" test_ref="oval:org.mitre.oval:tst:1199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1070" version="2" class="vulnerability">
      <metadata>
        <title>Exchange Server 2003,SP2 when running Outlook Web Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1193" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1193"/>
        <description>Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:11.495-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:59.631-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Exchange Server 2003,SP2 is installed." negate="false" test_ref="oval:org.mitre.oval:tst:1202"/>
        <criterion comment="mdbmsg.dll is less than 6.5.7650.28" negate="false" test_ref="oval:org.mitre.oval:tst:1201"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:107" version="1" class="vulnerability">
      <metadata>
        <title>Ximian Evolution Mail User Agent uuencoded header Denial of Service</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ximian Evolution</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0128" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0128"/>
        <description>The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malicious uuencoded (UUE) header, possibly triggering a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-11T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="evolution version is less than 1.2.2-5" negate="false" test_ref="oval:org.mitre.oval:tst:2939"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1069" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft PowerPoint 2003 Remote Code Execution Using a Malformed Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft PowerPoint</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0022"/>
        <description>Unspecified vulnerability in Microsoft PowerPoint in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP1 and SP2, Office 2004 for Mac, and v. X for Mac allows user-assisted attackers to execute arbitrary code via a PowerPoint document with a malformed record, which triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Operator on path element of obj:850 (referenced by tst:1204) fixed: was pattern match, now equals.  Thanks to John Hoyland of Centenial Software.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:553 (referenced by tst:1203) fixed: owerpnt.exe to powerpnt.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:11.276-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:59.038-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="PowerPoint 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1204"/>
        <criterion comment="the version of PowerPnt.exe is less than 11.0.8024.0" negate="false" test_ref="oval:org.mitre.oval:tst:1203"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1068" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Internet Printing ISAPI Extension Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0241" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0241"/>
        <description>Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-14T12:00:00.000-04:00" comment="modified wft-340 - added .dll to end of literal string as needed">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-01-20T01:23:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" negate="false" test_ref="oval:org.mitre.oval:tst:1205"/>
        <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1067" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft JScript Memory Corruption Vulnerability (WinS03)</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:11.115-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:58.565-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of Jscript.dll is less than 5.6.0.8831" negate="false" test_ref="oval:org.mitre.oval:tst:1206"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1066" version="1" class="vulnerability">
      <metadata>
        <title>DCOM RPC Object Identity Windows 2003 Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0124"/>
        <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="the version of comsvcs.dll is less than 2001.12.4720.130" negate="false" test_ref="oval:org.mitre.oval:tst:1207"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1065" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Format String Vulnerabilities in neon and Dependent Products</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0179"/>
        <description>Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="modified upt-36 - Fixed typo: oofice should have been ooffice">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-09-20T04:01:00.000-04:00" comment="modified upt-37 - Fixed typo--oofice should have been ooffice">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-09-20T04:02:00.000-04:00" comment="modified upt-38 - Fixed typo--oofice should have been ooffice">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-09-20T04:03:00.000-04:00" comment="modified cmp-940 - Fixed comment typo--oofice should have been ooffice">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="openoffice version is less than 1.1.0-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1223"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="OpenOffice Permissions">
            <criteria operator="OR" comment="/usr/bin/oocalc is executable">
              <criterion comment="/usr/bin/oocalc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1222"/>
              <criterion comment="/usr/bin/oocalc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1221"/>
              <criterion comment="/usr/bin/oocalc is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1220"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/oodraw is executable">
              <criterion comment="/usr/bin/oodraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1219"/>
              <criterion comment="/usr/bin/oodraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1218"/>
              <criterion comment="/usr/bin/oodraw is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1217"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ooffice is executable">
              <criterion comment="/usr/bin/ooffice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1216"/>
              <criterion comment="/usr/bin/ooffice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1215"/>
              <criterion comment="/usr/bin/ooffice is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1214"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/ooimpress is executable">
              <criterion comment="/usr/bin/ooimpress is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1213"/>
              <criterion comment="/usr/bin/ooimpress is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1212"/>
              <criterion comment="/usr/bin/ooimpress is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1211"/>
            </criteria>
            <criteria operator="OR" comment="/usr/bin/oowriter is executable">
              <criterion comment="/usr/bin/oowriter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1210"/>
              <criterion comment="/usr/bin/oowriter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1209"/>
              <criterion comment="/usr/bin/oowriter is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1208"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1064" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP WMF/EMF Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Enhanced Metafile (EMF)</product>
          <product>Windows Metafile (WMF)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0906" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0906"/>
        <description>Buffer overflow in the rendering for (1) Windows Metafile (WMF) or (2) Enhanced Metafile (EMF) image formats in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1 allows remote attackers to execute arbitrary code via a malformed WMF or EMF image.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:27:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="a vulnerable version of mf3216.dll exists on XP">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of mf3216.dll exists">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of mf3216.dll exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and mf3216.dll is less than 5.1.2600.132">
                <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                <criterion comment="the version of mf3216.dll is less than 5.1.2600.132" negate="false" test_ref="oval:org.mitre.oval:tst:1225"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and mf3216.dll is less than 5.1.2600.1331">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of mf3216.dll is less than 5.1.2600.1331" negate="false" test_ref="oval:org.mitre.oval:tst:1224"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and mf3216.dll is less than 5.1.2600.1331">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of mf3216.dll is less than 5.1.2600.1331" negate="false" test_ref="oval:org.mitre.oval:tst:1224"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1063" version="1" class="vulnerability">
      <metadata>
        <title>WMF Rendering Code Execution Vulnerability (Windows 2000)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2123"/>
        <description>Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that lead to heap-based buffer overflows, as demonstrated using MRBP16::bCheckRecord.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-09T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-11-10T07:06:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-12-01T06:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-16T01:04:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criteria operator="OR" comment="version of Gdi32.dll is less than 5.0.2195.7069 OR the version of Mf3216.dll is less than 5.0.2195.6898">
          <criterion comment="the version of Gdi32.dll is less than 5.0.2195.7069" negate="false" test_ref="oval:org.mitre.oval:tst:1227"/>
          <criterion comment="the version of Mf3216.dll is less than 5.0.2195.6898" negate="false" test_ref="oval:org.mitre.oval:tst:1226"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1062" version="1" class="vulnerability">
      <metadata>
        <title>DCOM RPC Object Identity Windows 2000 Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0124"/>
        <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of comsvcs.dll is less than 2000.2.3511.0" negate="false" test_ref="oval:org.mitre.oval:tst:1228"/>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1061" version="1" class="vulnerability">
      <metadata>
        <title>IE6:XP,SP2 COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1990" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1990"/>
        <description>Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not ActiveX controls, including (1) devenum.dll, (2) diactfrm.dll, (3) wmm2filt.dll, (4) fsusd.dll, (5) dmdskmgr.dll, (6) browsewm.dll, (7) browseui.dll, (8) shell32.dll, (9) mshtml.dll, (10) inetcfg.dll, (11) infosoft.dll, (12) query.dll, (13) syncui.dll, (14) clbcatex.dll, (15) clbcatq.dll, (16) comsvcs.dll, and (17) msconf.dll, which causes memory corruption, aka "COM Object Instantiation Memory Corruption Vulnerability," a different vulnerability than CVE-2005-2087.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-23T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-08-25T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed reference to patch kb896727 from criteria.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6.0 Installed XP SP2" negate="false" test_ref="oval:org.mitre.oval:tst:2403"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2900.2722" negate="false" test_ref="oval:org.mitre.oval:tst:2331"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1060" version="1" class="vulnerability">
      <metadata>
        <title>Directory Traversal Vulnerability in CVS Server</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0405" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0405"/>
        <description>CVS before 1.11 allows CVS clients to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests, a different vulnerability than CVE-2004-0180.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-18" negate="false" test_ref="oval:org.mitre.oval:tst:1255"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:106" version="1" class="vulnerability">
      <metadata>
        <title>Various Ethereal Dissector Vulnerabilities</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0432" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0432"/>
        <description>Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1059" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Certificate Validation Flaw Identity Spoofing Vulnerability (Variant)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Certificate Validation</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1183" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1183"/>
        <description>Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2004-07-14T12:00:00.000-04:00" comment="Changed to DRAFT">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-08-26T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows NT Server 4.0, Terminal Server Edition is installed">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
        </criteria>
        <criterion comment="the version of cryptdlg.dll is less then 5.0.1558.6072" negate="false" test_ref="oval:org.mitre.oval:tst:1229"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1057" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP HTML Help Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>HTML Help Facility</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1208"/>
        <description>Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as demonstrated using a "ms-its:" URL in Internet Explorer.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criteria operator="OR" comment="a vulnerable version of hh.exe exists">
          <criteria operator="AND" comment="for specific Windows configurations a vulnerable version of hh.exe exists">
            <criteria operator="OR" comment="32-bit version of Windows or 64-bit (itanium architecture) version of Windows is installed">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            </criteria>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
            <criterion comment="the version of hh.exe is less than 5.2.3790.315" negate="false" test_ref="oval:org.mitre.oval:tst:2671"/>
          </criteria>
          <criteria operator="AND" comment="for 32-bit Windows with sp2 a vulnerable version of hh.exe exists">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criterion comment="the version of hh.exe is less than 5.2.3790.2453" negate="false" test_ref="oval:org.mitre.oval:tst:1230"/>
          </criteria>
          <criteria operator="AND" comment="for 64-bit (x64 arch) Windows (gold edition) a vulnerable version of hh.exe exists">
            <criterion comment="64-Bit (x64 architecture) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2744"/>
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="the version of hh.exe is less than 5.2.3790.2435" negate="false" test_ref="oval:org.mitre.oval:tst:2669"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb896358 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:2668"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1056" version="1" class="vulnerability">
      <metadata>
        <title>Microsoft Certificate Validation Flaw Identity Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft CryptoAPI</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0862" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0862"/>
        <description>The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-07-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-13T12:00:00.000-04:00" comment="Added superceding patch info.">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-08-04T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T12:00:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-06-02T12:00:00.000-04:00" comment="Added product">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-06-08T03:17:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-29T06:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the version of crypt32.dll is less than 5.131.2600.1123" negate="false" test_ref="oval:org.mitre.oval:tst:1232"/>
        <criterion comment="the patch Q329115 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1231"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1054" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP winlogon Remote Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows logon process (winlogon)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0806" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0806"/>
        <description>Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:26:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of msgina.dll exists">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of msgina.dll exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of msgina.dll exists depending on service pack level">
                <criteria operator="AND" comment="no service pack is installed and msgina.dll is less than 5.1.2600.128">
                  <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                  <criterion comment="the version of msgina.dll is less than 5.1.2600.128" negate="false" test_ref="oval:org.mitre.oval:tst:1234"/>
                </criteria>
                <criteria operator="AND" comment="service pack 1 is installed and msgina.dll is less than 5.1.2600.1343">
                  <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                  <criterion comment="the version of msgina.dll is less than 5.1.2600.1343" negate="false" test_ref="oval:org.mitre.oval:tst:1233"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and msgina.dll is less than 5.1.2600.1343">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of msgina.dll is less than 5.1.2600.1343" negate="false" test_ref="oval:org.mitre.oval:tst:1233"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="machine is a member of a domain" negate="false" test_ref="oval:org.mitre.oval:tst:1494"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1053" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (32-Bit) DUNZIP Integer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Compressed Folders</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0575" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0575"/>
        <description>Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-10-20T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wrt-554 - corrected regular exprsssion on value. Needed to escape the period in the file name and change the *'s to .*">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-05-05T12:00:00.000-04:00" comment="Removed the negate=&quot;true&quot; from the config test; should be vulnerable *if* enabled, rather than vulnerable if *not*  enabled.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-05-11T05:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-06-01T03:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          <criteria operator="OR" comment="vulnerable 32-bit version of zipfldr.dll">
            <criteria operator="AND" comment="no service pack and vulnerable 32-bit version of zipfldr.dll">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="the 32-bit version of zipfldr.dll is less than 6.0.2750.167" negate="false" test_ref="oval:org.mitre.oval:tst:1238"/>
            </criteria>
            <criteria operator="AND" comment="service pack 1 and vulnerable 32-bit version of zipfldr.dll">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the 32-bit version of zipfldr.dll is less than 6.0.2800.1584" negate="false" test_ref="oval:org.mitre.oval:tst:1237"/>
            </criteria>
          </criteria>
          <criterion comment="the patch q873376 is installed (Hotfix key)" negate="true" test_ref="oval:org.mitre.oval:tst:1236"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Compressed Folders with zipfldr.dll are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1235"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1052" version="1" class="vulnerability">
      <metadata>
        <title>Multiple Vulnerabilities in Rockliffe MailSite Express</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Rockliffe MailSite Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3428" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3428"/>
        <description>Cross-site scripting (XSS) vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to inject arbitrary web script or HTML via a message body.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-25T07:14:00.000-04:00">
              <contributor organization="OS2A">Rahul Mohandas</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="the software MailSite Express version 6.1.20 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1239"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1051" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS Directory Traversal Command Execution (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" negate="false" test_ref="oval:org.mitre.oval:tst:1240"/>
        <criterion comment="Patch Q293826 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3020"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1049" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat OpenSSL Kerberos Handshake Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>OpenSSL</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0112" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0112"/>
        <description>The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </submitted>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="The MITRE Corporation">Matt Busby</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="openssl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1484"/>
        <criterion comment="openssl-devel version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1483"/>
        <criterion comment="openssl-perl version is less than 0.9.7a-20" negate="false" test_ref="oval:org.mitre.oval:tst:1482"/>
        <criterion comment="openssl096 version is less than 0.9.6-25.9" negate="false" test_ref="oval:org.mitre.oval:tst:1481"/>
        <criterion comment="openssl096b version is less than 0.9.6b-15" negate="false" test_ref="oval:org.mitre.oval:tst:1480"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1048" version="1" class="vulnerability">
      <metadata>
        <title>SNMP Trap Handling Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <product>snmpdx</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0012" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0012"/>
        <description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite.  NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor.  This and other SNMP-related candidates will be updated when more accurate information is available.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-02-01T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Brian Soby</contributor>
            </submitted>
            <status_change date="2005-02-01T08:41:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-09T07:56:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Solaris 7 or 8 installed">
            <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          </criteria>
          <criterion comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:1243"/>
          <criterion comment="Patch 107709-18 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1242"/>
          <criterion comment="Patch 108869-15 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1241"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="snmpdx running" negate="false" test_ref="oval:org.mitre.oval:tst:3124"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1046" version="1" class="vulnerability">
      <metadata>
        <title>Windows Utility Manager Shatter Message Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Utility Manager</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0908" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0908"/>
        <description>The Utility Manager in Microsoft Windows 2000 executes winhlp32.exe with system privileges, which allows local users to execute arbitrary code via a "Shatter" style attack using a Windows message that accesses the context sensitive help button in the GUI, as demonstrated using the File Open dialog in the Help window, a different vulnerability than CVE-2004-0213.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="the version of umandlg.dll is less than 1.0.0.4" negate="false" test_ref="oval:org.mitre.oval:tst:1244"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1045" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Print Spooler Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Print Spooler Service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1984"/>
        <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criterion comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1247"/>
        <criterion comment="the version of Spoolsv.exe is less than 5.0.2195.7059" negate="false" test_ref="oval:org.mitre.oval:tst:1246"/>
        <criterion comment="the patch KB896423 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1245"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1044" version="1" class="vulnerability">
      <metadata>
        <title>Solaris Xsun Privilege Escalation via Pixmaps Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>X</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2495" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2495"/>
        <description>Multiple integer overflows in XFree86 before 4.3.0 allow user-assisted attackers to execute arbitrary code via a crafted pixmap image.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-12T01:16:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="OR">
          <criteria operator="AND" comment="Solaris 8 (SPARC,Xsun) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
            <criterion comment="Patch 108652-94 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1254"/>
            <criterion comment="File Xorg exists" negate="true" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (SPARC,Xsun) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
            <criterion comment="Patch 112785-52 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1253"/>
            <criterion comment="File Xorg exists" negate="true" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (SPARC,Xsun) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
            <criterion comment="Patch 119059-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1252"/>
            <criterion comment="File Xorg exists" negate="true" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 8 (x86,Xsun) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 108653-83 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1251"/>
            <criterion comment="File Xorg exists" negate="true" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 9 (x86,Xsun) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 112786-41 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1250"/>
            <criterion comment="File Xorg exists" negate="true" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
          <criteria operator="AND" comment="Solaris 10 (x86,Xsun) meets Sun Alert ID 101926 criteria.">
            <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
            <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
            <criterion comment="Patch 119060-08 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:1249"/>
            <criterion comment="File Xorg exists" negate="true" test_ref="oval:org.mitre.oval:tst:1336"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="The Xsun X server is running" negate="false" test_ref="oval:org.mitre.oval:tst:1248"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1042" version="1" class="vulnerability">
      <metadata>
        <title>Malicious CVS Server RCS diff File Vulnerability in CVS Client</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0180" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0180"/>
        <description>The client for CVS before 1.11 allows a remote malicious CVS server to create arbitrary files using certain RCS diff files that use absolute pathnames during checkouts or updates, a different vulnerability than CVE-2004-0405.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-10T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
          <criterion comment="cvs version is less than 1.11.2-18" negate="false" test_ref="oval:org.mitre.oval:tst:1255"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1041" version="1" class="vulnerability">
      <metadata>
        <title>DCOM RPC Object Identity Windows NT Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Remote Procedure Call (RPC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0124" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0124"/>
        <description>The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-04-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criteria operator="OR" comment="a vulnerable version of ole32.dll exists on NT">
          <criteria operator="AND" comment="non Terminal Server and ole32.dll is less than 4.0.1381.7263">
            <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of ole32.dll is less than 4.0.1381.7263" negate="false" test_ref="oval:org.mitre.oval:tst:1257"/>
          </criteria>
          <criteria operator="AND" comment="Terminal Server and ole32.dll is less than 4.0.1381.33562">
            <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
            <criterion comment="the version of ole32.dll is less than 4.0.1381.33562" negate="false" test_ref="oval:org.mitre.oval:tst:1256"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1039" version="1" class="vulnerability">
      <metadata>
        <title>MDAC SQL-DMO Buffer Overflow (Test 3)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Data Access Components 2.7</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <modified date="2004-07-20T12:00:00.000-04:00" comment="Changed patch registry key value to IsInstalled">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Affected MDAC versions">
          <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9001.40" negate="false" test_ref="oval:org.mitre.oval:tst:1260"/>
          <criterion comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" negate="false" test_ref="oval:org.mitre.oval:tst:1259"/>
          <criterion comment="DataAccess Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1258"/>
        </criteria>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1038" version="1" class="vulnerability">
      <metadata>
        <title>RHE3 Fetchmail Buffer Overflow via Long UIDL Responses</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>fetchmail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2335" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2335"/>
        <description>Buffer overflow in the POP3 client in Fetchmail before 6.2.5.2 allows remote POP3 servers to cause a denial of service and possibly execute arbitrary code via long UIDL responses.  NOTE: a typo in an advisory accidentally used the wrong CVE identifier for the Fetchmail issue. This is the correct identifier.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-15T04:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2005-08-19T10:05:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2483"/>
          <criterion comment="fetchmail RPM older than 0:6.2.0-3.el3.1" negate="false" test_ref="oval:org.mitre.oval:tst:1262"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="/usr/bin/fetchmail is executable by any user" negate="false" test_ref="oval:org.mitre.oval:tst:1261"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1037" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Privilege Escalation via XBL.method.eval</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1735" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1735"/>
        <description>Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-05-07T09:05:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-05-10T08:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:10.798-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1268"/>
          <criterion comment="Firefox version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1267"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1266"/>
          <criterion comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1265"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.12 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1264"/>
          <criterion comment="Mozilla Suite version 1.7.12 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1263"/>
        </criteria>
        <criteria operator="AND" comment="A pre-release of SeaMonkey 1.0 is installed">
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2439"/>
          <criterion comment="A pre-release of SeaMonkey 1.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2438"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1035" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Kernel ncp_lookup Function BO</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0010"/>
        <description>Stack-based buffer overflow in the ncp_lookup function for ncpfs in Linux kernel 2.4.x allows local users to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.21-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1315"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1033" version="1" class="vulnerability">
      <metadata>
        <title>SquirrelMail SQL Injection Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0521" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0521"/>
        <description>SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-11T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1327"/>
          <criterion comment="php rpm is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1326"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
          <criterion comment="/etc/httpd/modules/libphp4.so exists" negate="false" test_ref="oval:org.mitre.oval:tst:1325"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1032" version="2" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 Help and Support Center HCP URL Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0199"/>
        <description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-05-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:20.916-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="the version of helpctr.exe is less than 5.2.3790.161" negate="false" test_ref="oval:org.mitre.oval:tst:1272"/>
          <criterion comment="the patch kb840374 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1320"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the HCP Protocol is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1031" version="2" class="vulnerability">
      <metadata>
        <title/>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="MISC" ref_id="http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=c00622788"/>
        <description>An undisclosed vulnerability has been identified in swagentd that could potentially be exploited remotely by an unauthenticated attacker to cause swagentd to abort.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:14:06.982-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:57.927-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.00 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_29963 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_29963 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3649"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_28847 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_28847 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3993"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1030" version="1" class="vulnerability">
      <metadata>
        <title>Windows Server 2003 COM Internet Services/RPC over HTTP Proxy Component Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>COM Internet Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0807" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0807"/>
        <description>Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-25T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-18T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-02T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows Server 2003 (excluding WinXP 64-bit, Version 2003) is installed">
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
            <criterion comment="this is an NT Workstation" negate="true" test_ref="oval:org.mitre.oval:tst:2703"/>
          </criteria>
          <criteria operator="OR" comment="a vulnerable version of rpcproxy.dll exists on Server 2003">
            <criterion comment="machine has followed the GDR update path and rpcproxy.dll is less than 5.2.3790.137" negate="false" test_ref="oval:org.mitre.oval:tst:1274"/>
            <criterion comment="machine has followed the QFE update path and rpcproxy.dll is less than 5.2.3790.141" negate="false" test_ref="oval:org.mitre.oval:tst:1273"/>
          </criteria>
          <criterion comment="the patch kb828741 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1499"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="COM Internet Services are enabled" negate="false" test_ref="oval:org.mitre.oval:tst:1383"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:103" version="1" class="vulnerability">
      <metadata>
        <title>Windows RPC Locator Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Locator service</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0003"/>
        <description>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-27T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="this is an NT Terminal Server" negate="true" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="the version of locator.exe is less than 4.0.1381.7202" negate="false" test_ref="oval:org.mitre.oval:tst:2942"/>
          <criterion comment="Patch Q810833 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2941"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Locator Enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2940"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1029" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="InternetSrvcs.INETSVCS-RUN, InternetSrvcs.INET-ENG-A-MAN, or VirtualVaultOS.VVOS-AUX-IA (B.11.04) is installed">
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1279"/>
          <criterion comment="InternetSrvcs.INET-ENG-A-MAN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1278"/>
          <criterion comment="VirtualVaultOS.VVOS-AUX-IA is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1277"/>
        </criteria>
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
          <criteria operator="AND" comment="700 Series OS Release 11.04">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHNE_24395 or later is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1275"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1028" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6.0 for Server 2003 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:57:00.000-04:00" comment="modified wft-184 - Deleted extra character in Build section">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Outlook Express 6 for Windows 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2855"/>
        <criterion comment="the version of inetcomm.dll is less than 6.00.3790.137" negate="false" test_ref="oval:org.mitre.oval:tst:1281"/>
        <criterion comment="the patch kb837009 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1280"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1027" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 DirectPlay Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft DirectPlay</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0202" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0202"/>
        <description>IDirectPlay4 Application Programming Interface (API) of Microsoft DirectPlay 7.0a thru 9.0b, as used in Windows Server 2003 and earlier allows remote attackers to cause a denial of service (application crash) via a malformed packet.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-11T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
        <criteria operator="OR" comment="Vulnerable versions of DirectX">
          <criteria operator="AND" comment="Unpatched DirectX 7.0">
            <criterion comment="DirectX 7.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1296"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.0.2195.6927" negate="false" test_ref="oval:org.mitre.oval:tst:1295"/>
            <criterion comment="Patch Windows2000-KB839643-x86-ENU.EXE Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1294"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 8.0x">
            <criterion comment="DirectX 8.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1293"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.0.2258.410" negate="false" test_ref="oval:org.mitre.oval:tst:1292"/>
            <criterion comment="Patch DirectX80-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1291"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 8.1x">
            <criterion comment="DirectX 8.1x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1290"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.1.2600.891" negate="false" test_ref="oval:org.mitre.oval:tst:1289"/>
            <criterion comment="Patch DirectX81-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1288"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 8.2x">
            <criterion comment="DirectX 8.2x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1287"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.2.3677.144" negate="false" test_ref="oval:org.mitre.oval:tst:1286"/>
            <criterion comment="Patch DirectX82-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1285"/>
          </criteria>
          <criteria operator="AND" comment="Unpatched DirectX 9.0x">
            <criterion comment="DirectX 9.0x Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1284"/>
            <criterion comment="File %windir%\system32\dplayx.dll version is less than 5.3.0.903" negate="false" test_ref="oval:org.mitre.oval:tst:1283"/>
            <criterion comment="Patch DirectX90-KB839643-x86-ENU Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1282"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1026" version="1" class="vulnerability">
      <metadata>
        <title>IE5.01,SP3 File Disclosure via Redirects Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0648" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0648"/>
        <description>The legacy &lt;script> data-island capability for XML in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to read arbitrary XML files, and portions of other files, via a URL whose "src" attribute redirects to a local file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-06-22T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-06-22T12:38:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-07-27T10:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-08-18T07:37:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 5.01 Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3015"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3541.2700" negate="false" test_ref="oval:org.mitre.oval:tst:2751"/>
          <criterion comment="the patch kb883939 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2750"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1025" version="1" class="vulnerability">
      <metadata>
        <title>Incorrect Permission on SQL Server Service Account Registry Key</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>SQL Server 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0642" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0642"/>
        <description>The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on SQL Server Service Account Registry Key."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-15T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-418 - Added space to registry key. used to say &quot;AppPath&quot; I changed it to &quot;App Path&quot;">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T10:31:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-08T12:00:00.000-04:00" comment="modified wft-418 - wft-418 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-419 - wft-419 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-420 - wft-420 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-428 - wft-428 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-429 - wft-429 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:31:00.000-04:00" comment="modified wft-430 - wft-430 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified date="2005-04-08T10:34:00.000-04:00" comment="modified wft-431 - wft-431 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="SQL Server 2000 installed" negate="false" test_ref="oval:org.mitre.oval:tst:2591"/>
        <criterion comment="the version of sqlservr.exe is less than 2000.80.650.0" negate="false" test_ref="oval:org.mitre.oval:tst:1303"/>
        <criterion comment="the version of odsole70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:1302"/>
        <criterion comment="the version of xpqueue.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:1301"/>
        <criterion comment="the version of xprepl.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:1300"/>
        <criterion comment="the version of xplog70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:1299"/>
        <criterion comment="the version of xpweb70.dll is less than 2000.80.606.0" negate="false" test_ref="oval:org.mitre.oval:tst:1298"/>
        <criterion comment="the version of xpstar.dll is less than 2000.80.628.0" negate="false" test_ref="oval:org.mitre.oval:tst:1297"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1024" version="1" class="vulnerability">
      <metadata>
        <title>The Remote Access Service is Running</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>NetBIOS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0621" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0621"/>
        <description>A component service related to NETBIOS is running.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-18T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows NT or 2000 Installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="NetBIOS enabled">
            <criterion comment="NetBIOS Bind not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:1306"/>
            <criterion comment="NetBIOS Export not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:1305"/>
            <criterion comment="NetBIOS Route not disabled" negate="false" test_ref="oval:org.mitre.oval:tst:1304"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1023" version="2" class="vulnerability">
      <metadata>
        <title>WinNT Broad Permissions for Remote Registry Access</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Windows NT</product>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0562" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0562"/>
        <description>The registry in Windows NT can be accessed remotely by users who are not administrators.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-03T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 907 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:20.085-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
          <criterion comment="Win2K/XP/2003 service pack 3 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3079"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Remote access to registry not controlled" negate="false" test_ref="oval:org.mitre.oval:tst:1307"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1022" version="1" class="vulnerability">
      <metadata>
        <title>MS Exchange Server Broad Permissions in WinReg Registry Key</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-0049" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0049"/>
        <description>Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-26T12:35:00.000-04:00" comment="modified wft-417 - Changed test to match comment">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Microsoft Exchange 2000 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:1311"/>
          <criterion comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" negate="false" test_ref="oval:org.mitre.oval:tst:1310"/>
          <criterion comment="Patch Q316056 installed" negate="true" test_ref="oval:org.mitre.oval:tst:1309"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="Everyone group given remote access permissions" negate="false" test_ref="oval:org.mitre.oval:tst:1308"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1021" version="1" class="vulnerability">
      <metadata>
        <title>NT4.0 Remote Registry Access Authentication Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Windows NT</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2000-0377" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-0377"/>
        <description>The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malformed request, which causes the winlogon process to fail, aka the "Remote Registry Access Authentication" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-03T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-06-30T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-07-12T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
        <criteria operator="AND" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition">
          <criterion comment="File %windir%\system32\winlogon.exe version is less than 4.0.1381.7058" negate="false" test_ref="oval:org.mitre.oval:tst:1313"/>
          <criterion comment="Windows NT 4.0 Security Roll-up Package" negate="true" test_ref="oval:org.mitre.oval:tst:3036"/>
        </criteria>
        <criteria operator="AND" comment="For Terminal Server">
          <criterion comment="this is an NT Terminal Server" negate="false" test_ref="oval:org.mitre.oval:tst:3097"/>
          <criterion comment="Windows NT Server 4.0, Terminal Server Edition Security Rollup Package" negate="true" test_ref="oval:org.mitre.oval:tst:1312"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1020" version="1" class="vulnerability">
      <metadata>
        <title>IE6 Double Byte Character Parsing Memory Corruption (WinXP)</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1189" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1189"/>
        <description>Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with double-byte characters, aka the "Double Byte Character Parsing Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Windows XP (64-bit,SP1 or 32-bit,SP2) is installed">
          <criteria operator="AND" comment="Windows XP 32 bit Service Pack 2">
            <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
            <criteria operator="AND" comment="Windows XP 32-bit edition is installed">
              <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="Windows XP 64-bit with Service Pack 1">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
          </criteria>
        </criteria>
        <criterion comment="the version of mshtml.dll is less than 6.0.2900.2873" negate="false" test_ref="oval:org.mitre.oval:tst:2339"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:102" version="1" class="vulnerability">
      <metadata>
        <title>Solaris 7 rpc.yppasswdd Buffer Overrun Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <product>rpc.yppasswdd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0779"/>
        <description>Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access via a long username.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-10-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="File rpc.yppasswdd exists" negate="false" test_ref="oval:org.mitre.oval:tst:3006"/>
          <criterion comment="Patch 111590-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:2943"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="rpc.yppasswdd running" negate="false" test_ref="oval:org.mitre.oval:tst:3004"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1018" version="1" class="vulnerability">
      <metadata>
        <title>Windows NT IIS Directory Traversal Command Execution (Test 2)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0333" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0333"/>
        <description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS 4.0 Major Version" negate="false" test_ref="oval:org.mitre.oval:tst:3099"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" negate="false" test_ref="oval:org.mitre.oval:tst:1314"/>
        <criterion comment="Patch Q295534 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3038"/>
        <criterion comment="Patch Q301625 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3037"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1017" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Kernel R128 DRI Limits Checking Vulnerability</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0003" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0003"/>
        <description>Unknown vulnerability in Linux kernel before 2.4.22 allows local users to gain privileges, related to "R128 DRI limits checking."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.21-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1315"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1016" version="2" class="vulnerability">
      <metadata>
        <title>Win2k Domain Controller LSASS Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Lightweight Directory Access Protocol (LDAP)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0663" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0663"/>
        <description>Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2007-01-03T13:53:46.187-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 (domain controller) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
        </criteria>
        <criterion comment="the version of lsasrv.dll is less than 5.0.2195.6902" negate="false" test_ref="oval:org.mitre.oval:tst:1511"/>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1015" version="2" class="vulnerability">
      <metadata>
        <title>WinXP,SP2 Drag-and-Drop Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0053" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0053"/>
        <description>Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-19T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb890047, added check for shell32 version &lt; 6.0.2900.2578">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-06-13T03:10:00.000-04:00" comment="Removed duplicate Windows XP test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-06-14T07:41:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:14:06.165-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows XP service pack 2 (or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1318"/>
          </criteria>
          <criterion comment="the version of shell32.dll is less than 6.0.2900.2578" negate="false" test_ref="oval:org.mitre.oval:tst:1317"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
          <criterion comment="Drag-and-Drop disabled when set to 3" negate="true" test_ref="oval:org.mitre.oval:tst:1316"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1014" version="1" class="vulnerability">
      <metadata>
        <title>IE File Download Dialog Deception Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0875"/>
        <description>Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-29T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-05-25T04:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T04:00:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2004-09-22T04:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-09-22T04:01:00.000-04:00" comment="Replaced IE cumulative patch IDs to correspond to the original IDs">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-10-06T04:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Changed IE registry test to wrt-18">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="the version of mshtml.dll is less than 6.0.2712.0300" negate="false" test_ref="oval:org.mitre.oval:tst:1460"/>
          <criterion comment="Patch Q313675 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1459"/>
          <criterion comment="Patch Q316059.exe Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1458"/>
          <criterion comment="Patch Q319282 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1457"/>
          <criterion comment="the patch q321232 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3119"/>
          <criterion comment="the patch q323759 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3118"/>
          <criterion comment="the patch q328970 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3117"/>
          <criterion comment="the patch q324929 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3116"/>
          <criterion comment="the patch q810847 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3115"/>
          <criterion comment="the patch q813489 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3114"/>
          <criterion comment="the patch q818529 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3113"/>
          <criterion comment="the patch q822925 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3112"/>
          <criterion comment="the patch q828750 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3111"/>
          <criterion comment="the patch q824145 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:3110"/>
          <criterion comment="the patch q832894 is installed (Installed Components key)" negate="true" test_ref="oval:org.mitre.oval:tst:2588"/>
          <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3090"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File Downloads Not Disabled">
            <criterion comment="Use Machine Settings" negate="false" test_ref="oval:org.mitre.oval:tst:1456"/>
            <criterion comment="File Downloads Allowed In At Least One Zone" negate="false" test_ref="oval:org.mitre.oval:tst:1455"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1013" version="1" class="vulnerability">
      <metadata>
        <title>Red Hat Enterprise 3 Kernel Real Time Clock Data Leakage</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>Red Hat Enteprise Linux 3</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0984"/>
        <description>Real time clock (RTC) routines in Linux kernel 2.4.23 and earlier do not properly initialize their structures, which could leak kernel data to user space.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criterion comment="kernel version is less than 2.4.21-15.EL" negate="false" test_ref="oval:org.mitre.oval:tst:1342"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1012" version="1" class="vulnerability">
      <metadata>
        <title>SquirrelMail Cross-site Scripting Vulnerability II</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0520" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0520"/>
        <description>Cross-site scripting (XSS) vulnerability in mime.php for SquirrelMail before 1.4.3 allows remote attackers to insert arbitrary HTML and script via the content-type mail header, as demonstrated using read_body.php.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-11T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1327"/>
          <criterion comment="php rpm is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1326"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
          <criterion comment="/etc/httpd/modules/libphp4.so exists" negate="false" test_ref="oval:org.mitre.oval:tst:1325"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1011" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 IIS5 WebDAV Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1182"/>
        <description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-11T12:00:00.000-04:00" comment="modified wft-330 - changed the version of msw3prt.dll to test against from 5.5.2195.58075 to 5.0.2195.5807">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-01-20T01:18:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS minor version equals 0" negate="false" test_ref="oval:org.mitre.oval:tst:3098"/>
        <criterion comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" negate="false" test_ref="oval:org.mitre.oval:tst:1447"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1010" version="1" class="vulnerability">
      <metadata>
        <title>Outlook Express v6.0,SP1 MHTML URL Processing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0380"/>
        <description>The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to bypass domain restrictions and execute arbitrary code, as demonstrated on Internet Explorer using script in a compiled help (CHM) file that references the InfoTech Storage (ITS) protocol handlers such as (1) ms-its, (2) ms-itss, (3) its, or (4) mk:@MSITStore, aka the "MHTML URL Processing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook Express 6 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1355"/>
        <criterion comment="the version of inetcomm.dll is less than 6.00.2800.1409" negate="false" test_ref="oval:org.mitre.oval:tst:1319"/>
        <criterion comment="the patch kb837009 is installed (installed components key)" negate="true" test_ref="oval:org.mitre.oval:tst:1512"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:101" version="1" class="vulnerability">
      <metadata>
        <title>Ethereal 0-Length Buffer Size Vulnerability in tvb_get_nstring0()</title>
        <affected family="unix">
          <platform>Red Hat Linux 9</platform>
          <product>Ethereal</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0431" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0431"/>
        <description>The tvb_get_nstringz0 function in Ethereal 0.9.12 and earlier does not properly handle a zero-length buffer size, with unknown consequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-08-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-05-05T12:00:00.000-04:00" comment="Corrected syntax errors in sql verion of the definition.">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </modified>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Red Hat 9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3153"/>
        <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:3152"/>
        <criteria operator="OR" comment="Vulnerable Config">
          <criterion comment="ethereal version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2985"/>
          <criterion comment="ethereal-gnome version is less than 0.9.13-1.90.1" negate="false" test_ref="oval:org.mitre.oval:tst:2984"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1009" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP IIS5 WebDAV Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Information Server (IIS)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1182" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1182"/>
        <description>IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="IIS major version equals 5" negate="false" test_ref="oval:org.mitre.oval:tst:3081"/>
        <criterion comment="IIS 5.1 Minor Version" negate="false" test_ref="oval:org.mitre.oval:tst:1357"/>
        <criterion comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" negate="false" test_ref="oval:org.mitre.oval:tst:1356"/>
        <criterion comment="Patch Q327696 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3094"/>
        <criterion comment="Patch Q811114 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:3093"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1008" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Help and Support Center HCP URL Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0199" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0199"/>
        <description>Help and Support Center in Microsoft Windows XP and Windows Server 2003 SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code, as demonstrated using certain hcp:// URLs that access the DVD Upgrade capability (dvdupgrd.htm).</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-12T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-05-12T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:25:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:18.203-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of helpctr.exe exists on XP">
            <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of helpctr.exe exists">
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criteria operator="OR" comment="a vulnerable version of helpctr.exe exists exists depending on service pack level">
                <criteria operator="AND" comment="service pack 1 or earlier is installed and helpctr.exe is less than 5.1.2600.137">
                  <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
                  <criterion comment="the version of helpctr.exe is less than 5.1.2600.137" negate="false" test_ref="oval:org.mitre.oval:tst:1322"/>
                </criteria>
                <criteria operator="AND" comment="service pack 2 is installed and helpctr.exe is less than 5.1.2600.1515">
                  <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
                  <criterion comment="the version of helpctr.exe is less than 5.1.2600.1515" negate="false" test_ref="oval:org.mitre.oval:tst:1321"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="64-bit version of Windows and helpctr.exe is less than 5.1.2600.1515">
              <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
              <criterion comment="the version of helpctr.exe is less than 5.1.2600.1515" negate="false" test_ref="oval:org.mitre.oval:tst:1321"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb840374 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1320"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the HCP Protocol is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1477"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1007" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP ASN.1 Library Double-free Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft ASN.1 Library</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0123" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0123"/>
        <description>Double-free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
            <status_change date="2004-05-05T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:24:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="a vulnerable version of msasn1.dll exists">
          <criteria operator="AND" comment="32-bit version of Windows and a vulnerable version of msasn1.dll exists">
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criteria operator="OR" comment="a vulnerable version of msasn1.dll exists depending on service pack level">
              <criteria operator="AND" comment="no service pack is installed and msasn1.dll is less than 5.1.2600.137">
                <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
                <criterion comment="the version of msasn1.dll is less than 5.1.2600.137" negate="false" test_ref="oval:org.mitre.oval:tst:1324"/>
              </criteria>
              <criteria operator="AND" comment="service pack 1 is installed and msasn1.dll is less than 5.1.2600.1362">
                <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
                <criterion comment="the version of msasn1.dll is less than 5.1.2600.1362" negate="false" test_ref="oval:org.mitre.oval:tst:1323"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="AND" comment="64-bit version of Windows and msasn1.dll is less than 5.1.2600.1362">
            <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
            <criterion comment="the version of msasn1.dll is less than 5.1.2600.1362" negate="false" test_ref="oval:org.mitre.oval:tst:1323"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1006" version="1" class="vulnerability">
      <metadata>
        <title>SquirrelMail Cross-site Scripting Vulnerability I</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>SquirrelMail</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0519" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0519"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-11T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1327"/>
          <criterion comment="php rpm is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1326"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="httpd is listening on the network" negate="false" test_ref="oval:org.mitre.oval:tst:1630"/>
          <criterion comment="/etc/httpd/modules/libphp4.so exists" negate="false" test_ref="oval:org.mitre.oval:tst:1325"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1005" version="1" class="vulnerability">
      <metadata>
        <title>IE6,SP1 DHTML Method Heap Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0055" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0055"/>
        <description>Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruption Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-03-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2005-03-23T08:09:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-04-13T12:15:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-05-04T12:33:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-12-26T09:40:00.000-04:00" comment="Removed test to check kb867282.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-01-12T08:59:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Internet Explorer 6 Service Pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2919"/>
          <criteria operator="OR" comment="a vulnerable version of mshtml.dll exisits GDR/QFE">
            <criterion comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" negate="false" test_ref="oval:org.mitre.oval:tst:1329"/>
            <criterion comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" negate="false" test_ref="oval:org.mitre.oval:tst:1328"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="ActiveX controls and active scripting are enabled">
            <criteria operator="AND" comment="current user settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="true" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2917"/>
              <criterion comment="active scripting is enabled for the current user" negate="false" test_ref="oval:org.mitre.oval:tst:2812"/>
            </criteria>
            <criteria operator="AND" comment="local machine settings are being used and ActiveX controls and active scripting are enabled">
              <criterion comment="use machine settings rather than individual user settings" negate="false" test_ref="oval:org.mitre.oval:tst:2951"/>
              <criterion comment="ActiveX controls are enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2916"/>
              <criterion comment="active scripting is enabled for the local machine" negate="false" test_ref="oval:org.mitre.oval:tst:2811"/>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1004" version="2" class="vulnerability">
      <metadata>
        <title>WinXP Management Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Windows XP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0909" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0909"/>
        <description>Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:24:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-09-07T18:56:00.000-04:00" comment="set negate attribute to true in criteria for oval:org.mitre.oval:tst:2845">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-07T18:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:17.199-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="A vulnerable version of evtgprov.dll exists on XP">
          <criteria operator="AND" comment="No service pack is installed, 32 bit Edition, and evtgprov.dll is less than 5.1.2600.136">
            <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
            <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
            <criterion comment="the version of evtgprov.dll is less than 5.1.2600.136" negate="false" test_ref="oval:org.mitre.oval:tst:1331"/>
          </criteria>
          <criteria operator="AND" comment="Affected evtgprov.dll versions on Windows XP SP1">
            <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
            <criterion comment="the version of evtgprov.dll is less than 5.1.2600.1363" negate="false" test_ref="oval:org.mitre.oval:tst:1330"/>
          </criteria>
        </criteria>
        <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
        <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
          <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1003" version="1" class="vulnerability">
      <metadata>
        <title>CVS serve_notify Improper Handling of Empty Data Lines</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0418"/>
        <description>serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:1002" version="2">
      <metadata>
        <title>Microsoft XML Core Services 4 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft XML Core Services 4 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-10-11T05:29:41">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-13T14:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-31T19:35:29.444-05:00">INTERIM</status_change>
            <status_change date="2006-11-21T21:27:39.227-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft XML Core Services 4 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:30"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100117" version="1" class="vulnerability">
      <metadata>
        <title>libtiff Directory Entry Count Integer Overflow Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1308" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1308"/>
        <description>Integer overflow in (1) tif_dirread.c and (2) tif_fax3.c for libtiff 3.5.7 and 3.7.0 allows remote attackers to execute arbitrary code via a TIFF file containing a TIFF_ASCII or TIFF_UNDEFINED directory entry with a -1 entry count, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109932-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114219-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:205"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114220-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:202"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119900-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:201"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119901-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100116" version="1" class="vulnerability">
      <metadata>
        <title>libtiff Malloc Error Denial of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0886" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0886"/>
        <description>Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109932-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114219-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:205"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114220-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:202"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119900-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:201"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119901-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100115" version="1" class="vulnerability">
      <metadata>
        <title>libtiff tif_dirread divide-by-zero Denial of Service</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0804" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0804"/>
        <description>Vulnerability in tif_dirread.c for libtiff allows remote attackers to cause a denial of service (application crash) via a TIFF image that causes a divide-by-zero error when the number of row bytes is zero, a different vulnerability than CVE-2005-2452.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109932-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114219-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:205"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114220-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:202"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119900-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:201"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119901-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100114" version="1" class="vulnerability">
      <metadata>
        <title>libtiff RLE Decoder Buffer Overflow Vulnerabilities</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <platform>Sun Solaris 10</platform>
          <product>libtiff</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0803" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0803"/>
        <description>Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 7 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 118953-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:209"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 7 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 118954-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:208"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 109931-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:207"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 109932-10 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:206"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criteria operator="OR" comment="Solaris 9 (SPARC) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (SPARC) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114219-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:205"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criteria operator="OR" comment="Solaris 9 (x86) supporting criteria for Sun Alert ID 101677.">
            <criteria operator="AND" comment="Solaris 9 (x86) supporting CDE criteria for Sun Alert ID 101677.">
              <criterion comment="CDE Desktop Window Manager (SUNWdtwm) installed" negate="false" test_ref="oval:org.mitre.oval:tst:675"/>
              <criterion comment="Patch 114220-11 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:202"/>
            </criteria>
            <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
            <criterion comment="Pkg SUNWTiffx is installed" negate="false" test_ref="oval:org.mitre.oval:tst:203"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (SPARC) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119900-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:201"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 10 (x86) meets Sun Alert ID 101677 criteria.">
          <criterion comment="Solaris 10 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:2459"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Pkg SUNWTiff is installed" negate="false" test_ref="oval:org.mitre.oval:tst:204"/>
          <criterion comment="Patch 119901-01 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:200"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100113" version="1" class="vulnerability">
      <metadata>
        <title>X Display Manager DoS via Invalid XDMCP Request</title>
        <affected family="unix">
          <platform>Sun Solaris 7</platform>
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>XDM</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1347" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1347"/>
        <description>X Display Manager (XDM) on Solaris 8 allows remote attackers to cause a denial of service (XDM crash) via an invalid X Display Manager Control Protocol (XDMCP) request.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Added CVE #">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="Solaris 7 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3045"/>
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101549 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 111844-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:213"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101549 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 111845-03 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:212"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101549 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 112785-38 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:211"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101549 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 112786-27 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:210"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100112" version="1" class="vulnerability">
      <metadata>
        <title>Apache mod_proxy Content-Length Header Buffer Overflow</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0492" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0492"/>
        <description>Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116973-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:217"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 116974-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:216"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:215"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 114145-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:214"/>
        </criteria>
        <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100111" version="1" class="vulnerability">
      <metadata>
        <title>Apache Allow/Deny Parsing Error</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0993"/>
        <description>mod_access in Apache 1.3 before 1.3.30, when running big-endian 64-bit platforms, does not properly parse Allow/Deny rules using IP addresses without a netmask, which could allow remote attackers to bypass intended access restrictions.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116973-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:217"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:215"/>
        </criteria>
        <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100110" version="1" class="vulnerability">
      <metadata>
        <title>Apache Listening Socket Starvation Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0174" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0174"/>
        <description>Apache 1.4.x before 1.3.30, and 2.0.x before 2.0.49, when using multiple listening sockets on certain platforms, allows remote attackers to cause a denial of service (blocked new connections) via a "short-lived connection on a rarely-accessed listening socket."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116973-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:217"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 116974-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:216"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:215"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 114145-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:214"/>
        </criteria>
        <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100109" version="1" class="vulnerability">
      <metadata>
        <title>Apache Error Log Escape Sequence Filtering Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0020" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0020"/>
        <description>Apache does not filter terminal escape sequences from its error logs, which could make it easier for attackers to insert those sequences into terminal emulators containing vulnerabilities related to escape sequences.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116973-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:217"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 116974-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:216"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:215"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 114145-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:214"/>
        </criteria>
        <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100108" version="1" class="vulnerability">
      <metadata>
        <title>Apache Nonce Verification Response Replay Vulnerability</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <platform>Sun Solaris 9</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0987" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0987"/>
        <description>mod_digest for Apache before 1.3.31 does not properly verify the nonce of a client response by using a AuthNonce secret.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Solaris 8 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 116973-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:217"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 8 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 116974-02 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:216"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (SPARC) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="sparc architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2465"/>
          <criterion comment="Patch 113146-05 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:215"/>
        </criteria>
        <criteria operator="AND" comment="Solaris 9 (x86) meets Sun Alert ID 101555 criteria.">
          <criterion comment="Solaris 9 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3051"/>
          <criterion comment="ix86 architecture" negate="false" test_ref="oval:org.mitre.oval:tst:2463"/>
          <criterion comment="Patch 114145-04 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:214"/>
        </criteria>
        <criterion comment="Apache running (httpd)" negate="false" test_ref="oval:org.mitre.oval:tst:654"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100107" version="1" class="vulnerability">
      <metadata>
        <title>Firefox and Mozilla top.focus() Cross-Site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2266" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2266"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-07T04:00:00.000-04:00" comment="Added description">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-19T04:05:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
        <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100106" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false" test_ref="oval:org.mitre.oval:tst:219"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100105" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003,SP1 Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false" test_ref="oval:org.mitre.oval:tst:219"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100104" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of kerberos.dll is less than 5.2.3790.347" negate="false" test_ref="oval:org.mitre.oval:tst:218"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100103" version="1" class="vulnerability">
      <metadata>
        <title>Server 2003 Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="the version of kerberos.dll is less than 5.2.3790.347" negate="false" test_ref="oval:org.mitre.oval:tst:218"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100102" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 (64-bit) PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false" test_ref="oval:org.mitre.oval:tst:219"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100101" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 (64-bit) Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of kerberos.dll is less than 5.2.3790.2464" negate="false" test_ref="oval:org.mitre.oval:tst:219"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100100" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of kerberos.dll is less than 5.1.2600.2698" negate="false" test_ref="oval:org.mitre.oval:tst:220"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1001" version="1" class="vulnerability">
      <metadata>
        <title>Integer overflow in the "Max-dotdot" CVS protocol command</title>
        <affected family="unix">
          <platform>Red Hat Enterprise Linux 3</platform>
          <product>CVS</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0417" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0417"/>
        <description>Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-06-29T12:00:00.000-04:00">
              <contributor organization="Bastille Linux">Jay Beale</contributor>
            </submitted>
            <status_change date="2004-07-21T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-08-04T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Red Hat Enterprise 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2861"/>
          <criterion comment="cvs rpm version prior to 1.11.2-24 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1347"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="OR" comment="/usr/bin/cvs is executable">
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1381"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1380"/>
            <criterion comment="/usr/bin/cvs is executable" negate="false" test_ref="oval:org.mitre.oval:tst:1379"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100099" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP2 Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of kerberos.dll is less than 5.1.2600.2698" negate="false" test_ref="oval:org.mitre.oval:tst:220"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100098" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 (32-bit) PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of kerberos.dll is less than 5.1.2600.1701" negate="false" test_ref="oval:org.mitre.oval:tst:221"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100097" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 (32-bit) Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of kerberos.dll is less than 5.1.2600.1701" negate="false" test_ref="oval:org.mitre.oval:tst:221"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100096" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 PKINIT Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1982" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1982"/>
        <description>Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of kerberos.dll is less than 5.0.2195.7053" negate="false" test_ref="oval:org.mitre.oval:tst:222"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100095" version="1" class="vulnerability">
      <metadata>
        <title>Windows 2000 Kerberos Message DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1981" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1981"/>
        <description>Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Windows 2000 Service Pack 4 (or later) is installed">
          <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
          <criterion comment="Win2K/XP/2003 service pack 4 (or later) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3084"/>
        </criteria>
        <criterion comment="the version of kerberos.dll is less than 5.0.2195.7053" negate="false" test_ref="oval:org.mitre.oval:tst:222"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100092" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 (64-bit) RDP DoS Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1218" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1218"/>
        <description>The Microsoft Windows kernel in Microsoft Windows 2000 Server, Windows XP, and Windows Server 2003 allows remote attackers to cause a denial of service (crash) via crafted Remote Desktop Protocol (RDP) requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of rdpwd.sys is less than 5.2.3790.2465" negate="false" test_ref="oval:org.mitre.oval:tst:223"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100088" version="1" class="vulnerability">
      <metadata>
        <title>Test Consolidated to OVAL Definition 1297</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false" test_ref="oval:org.mitre.oval:tst:224"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100086" version="1" class="vulnerability">
      <metadata>
        <title>Test Consolidated to OVAL Definition 1075</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of tapisrv.dll is less than 5.2.3790.2483" negate="false" test_ref="oval:org.mitre.oval:tst:224"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100085" version="1" class="vulnerability">
      <metadata>
        <title>Test Consolidated to OVAL Definition 1075</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3019"/>
        <criterion comment="the version of tapisrv.dll is less than 5.1.2600.2716" negate="false" test_ref="oval:org.mitre.oval:tst:225"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100084" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 TAPI Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0058" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0058"/>
        <description>Buffer overflow in the Telephony Application Programming Interface (TAPI) for Microsoft Windows 98, Windows 98 SE, Windows ME, Windows 2000, Windows XP, and Windows Server 2003 allows attackers elevate privileges or execute arbitrary code via a crafted message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of tapisrv.dll is less than 5.1.2600.1715" negate="false" test_ref="oval:org.mitre.oval:tst:226"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100082" version="1" class="vulnerability">
      <metadata>
        <title>Test Consolidated to OVAL1221</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:227"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100081" version="1" class="vulnerability">
      <metadata>
        <title>Test Consolidated to OVAL790</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1989"/>
        <description>Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when browsing from a web site to a web folder view using WebDAV, aka "Web Folder Behaviors Cross-Domain Vulnerability".</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of mshtml.dll is less than 6.0.3790.2491" negate="false" test_ref="oval:org.mitre.oval:tst:227"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100077" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP,SP1 Print Spooler Service Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1984" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1984"/>
        <description>Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
        <criterion comment="the version of spoolsv.exe is less than 5.1.2600.1699" negate="false" test_ref="oval:org.mitre.oval:tst:228"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100073" version="1" class="vulnerability">
      <metadata>
        <title>Windows XP (64-bit) PnP Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1983" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1983"/>
        <description>Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1 allows remote attackers to execute arbitrary code via a crafted packet, and local users to gain privileges via a malicious application, as exploited by the Zotob (aka Mytob) worm.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="the version of umpnpmgr.dll is less than 5.2.3790.2477" negate="false" test_ref="oval:org.mitre.oval:tst:229"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100057" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Local File Loading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0141" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0141"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to load local files via links "with a custom getter and toString method" that are middle-clicked by the user to be opened in a new tab.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100056" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Creates World-readable temp Files</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0142"/>
        <description>Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10060 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7-1.7.3 is installed">
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:239"/>
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:238"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 is installed">
          <criterion comment="Firefox version 0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:233"/>
          <criterion comment="Mozilla Firefox version 0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:232"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.6-0.8 is installed">
          <criterion comment="Mozilla Thunderbird version 0.6-0.8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:231"/>
          <criterion comment="Mozilla Thunderbird version 0.6-0.8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:230"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100055" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla SSL Lock Image Spoofing during Binary Download</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0143"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:55:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100054" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla SSL Lock Image Spoofing via "View Source"</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0144" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0144"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:54:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100053" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Inactive Tab Form Data Theft Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1381" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1381"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:52:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100052" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Malicious news: Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1316" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1316"/>
        <description>Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of service (application crash) via an NNTP URL (news:) with a trailing '\' (backslash) character, which prevents a string from being NULL terminated.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Added CVE #">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:51:00.000-04:00" comment="Added Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.8 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:237"/>
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:236"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100051" version="1" class="vulnerability">
      <metadata>
        <title>Firefox Script-generated Download Prompt Bypass</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0145" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0145"/>
        <description>Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:49:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100050" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Inactive Tab Dialog Box Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1380" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1380"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the dialog boxes from web sites in other windows and facilitate phishing attacks, aka the "Dialog Box Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100049" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla 407 Proxy Information Disclosure Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0147" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0147"/>
        <description>Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows remote attackers to steal NTLM or SPNEGO credentials.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:47:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.4 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:235"/>
          <criterion comment="Mozilla Suite version 1.7.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:234"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100048" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Thunderbird Subject to IE Vulnerabilities via javascript</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0148"/>
        <description>Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is installed on the user's system.  NOTE: since the invocation between multiple products is a common practice, and the vulnerabilities inherent in multi-product interactions are not easily enumerable, this issue might be REJECTED in the future.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:46:00.000-04:00" comment="Added Thunderbird as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.8 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:237"/>
          <criterion comment="Mozilla Thunderbird version 0.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:236"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100047" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Mail News Cookie Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0149" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0149"/>
        <description>Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers bypass the user's intended privacy and security policy by using cookies in e-mail messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-25T04:03:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-01-25T07:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Thunderbird version 0.6-0.9 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 0.6-0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:241"/>
          <criterion comment="Mozilla Thunderbird version 0.6-0.9 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:240"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7-1.7.3 is installed">
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:239"/>
          <criterion comment="Mozilla Suite version 1.7-1.7.3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:238"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100046" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Livefeed Bookmark Cookie Swiping</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0150" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0150"/>
        <description>Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:44:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 0.9 or earlier is installed">
          <criterion comment="Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:243"/>
          <criterion comment="Mozilla Firefox version 0.9 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:242"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100045" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Popup Content Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1156"/>
        <description>Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:43:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100044" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla SSL Lock Image Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0593" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0593"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:42:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100043" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla UTF8 to Unicode Conversion Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0592" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0592"/>
        <description>Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:41:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100042" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Download/Security Dialogs Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0591" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0591"/>
        <description>Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-31T06:29:00.000-04:00" comment="Updated reference to CVE-2005-0591.  Set product to Mozilla.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-02-01T05:40:00.000-04:00" comment="Added Firefox to affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100041" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla 'user:pass@host' Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0590" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0590"/>
        <description>The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequence in the URL, which appears before the real hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:38:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100040" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla String Library Memory Overwrite Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0255" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0255"/>
        <description>String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers to cause a denial of service and possibly execute arbitrary code by forcing an out-of-memory state that causes a reallocation to fail and return a pointer to a fixed address, which leads to heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:37:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100039" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Autocomplete Data Leak</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0589" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0589"/>
        <description>The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors the values that are generated by the autocomplete capability.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:36:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100038" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla XSLT Stylesheet Information Disclosure Potential</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0588" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0588"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:35:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100037" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Double Download .lnk Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0587" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0587"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:34:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100036" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla "Save Link As" Dialog Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0586" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0586"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:33:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100035" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Download Dialog Source Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0585" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0585"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:32:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100034" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla HTTP auth Prompt Tab Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0584" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0584"/>
        <description>Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:31:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100033" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Image Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0230" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0230"/>
        <description>Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:30:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100032" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Cross-site Scripting via Drag and Drop to Tab</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0231" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0231"/>
        <description>Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:29:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100031" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Privileged Content Loading Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0527" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0527"/>
        <description>Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain XUL events when a user drags a scrollbar two times, aka "Firescrolling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:27:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100029" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla IDN Homograph Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0233" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0233"/>
        <description>The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-20T04:00:00.000-04:00" comment="Added CVE #">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:26:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla  Firefox version 1.0 or earlier is installed">
          <criterion comment="Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:245"/>
          <criterion comment="Mozilla Firefox version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:244"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100028" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla GIF Heap Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0399" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0399"/>
        <description>Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a crafted Netscape extension 2 block and buffer size.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:25:00.000-04:00" comment="Added Firefox, Mozilla, Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.1 or earlier is installed">
          <criterion comment="Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:251"/>
          <criterion comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:250"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:249"/>
          <criterion comment="Mozilla Thunderbird version 1.0 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:248"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.5 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:247"/>
          <criterion comment="Mozilla Suite version 1.7.5 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100027" version="1" class="vulnerability">
      <metadata>
        <title>Firefox Sidebar Panel Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0402" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0402"/>
        <description>Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:23:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.1 or earlier is installed">
          <criterion comment="Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:251"/>
          <criterion comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:250"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100026" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla XUL Drag and Drop Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0401" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0401"/>
        <description>FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:22:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.1 or earlier is installed">
          <criterion comment="Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:251"/>
          <criterion comment="Mozilla Firefox version 1.0.1 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:250"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100025" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Javascript "lambda"</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0989" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0989"/>
        <description>The find_replen function in jsstr.c in the the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:20:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100024" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla PLUGINSPAGE Privileged Javascript Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0752" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0752"/>
        <description>The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:19:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100023" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla blocked javascript: popup Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1153" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1153"/>
        <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-10-11T04:51:00.000-04:00" comment="modified wrt-10049 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:18:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100022" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Global Pollution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1154"/>
        <description>Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:17:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100021" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla favicons Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1155" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1155"/>
        <description>The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a &lt;LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:16:00.000-04:00" comment="Added Firefox, Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100020" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Search Plugin Cross-site Scripting Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1156" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1156"/>
        <description>Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:14:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100019" version="1" class="vulnerability">
      <metadata>
        <title>Firefox Sidebar Code Execution via _search Target</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1158" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1158"/>
        <description>Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:12:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100018" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla InstallTrigger Instance Validation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1159" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1159"/>
        <description>The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:11:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100017" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla DOM Node Privilege Escalation Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1160" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1160"/>
        <description>The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certain properties or methods of DOM nodes, as demonstrated using multiple attacks involving the eval function or the Script object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-10-11T04:51:00.000-04:00" comment="modified wrt-10049 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:10:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.6 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:253"/>
          <criterion comment="Mozilla Suite version 1.7.6 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:252"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100016" version="1" class="vulnerability">
      <metadata>
        <title>Mozilla Suite InstallTrigger Callback Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2263"/>
        <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-07T04:00:00.000-04:00" comment="Added description">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:09:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100015" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla JavaScript Wrapping Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1531" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1531"/>
        <description>Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10025 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:13:00.000-04:00" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:07:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-06T04:00:00.000-04:00" comment="Fixed ste:262 by properly anchoring the regular expression.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-06T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:56.769-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.3 or earlier is installed">
          <criterion comment="Firefox version 1.0.3 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:265"/>
          <criterion comment="Mozilla Firefox version 1.0.3 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:255"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.7 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:264"/>
          <criterion comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100014" version="2" class="vulnerability">
      <metadata>
        <title>Mozilla Script Privilege Context Vulnerabilities</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1532" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1532"/>
        <description>Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10025 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:13:00.000-04:00" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:06:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-06T04:00:00.000-04:00" comment="Fixed ste:262 by properly anchoring the regular expression.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-06T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:55.815-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.3 or earlier is installed">
          <criterion comment="Firefox version 1.0.3 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:265"/>
          <criterion comment="Mozilla Firefox version 1.0.3 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:255"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.7 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:264"/>
          <criterion comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:254"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100013" version="1" class="vulnerability">
      <metadata>
        <title>Improper Handling of Synthetic Events in Mozilla</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2260" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2260"/>
        <description>The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-generated events and untrusted synthetic events, which makes it easier for remote attackers to perform dangerous actions that normally could only be performed manually by the user.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:03:00.000-04:00" comment="Added Firefox and Mozilla as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100012" version="1" class="vulnerability">
      <metadata>
        <title>XBL Script Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
          <product>Thunderbird</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2261"/>
        <description>Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T05:01:00.000-04:00" comment="Added Firefox, Mozilla, and Thunderbird as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed">
          <criterion comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:257"/>
          <criterion comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:256"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100011" version="2" class="vulnerability">
      <metadata>
        <title>Firefox Wallpaper Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2262" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2262"/>
        <description>Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper" (in Firefox) or "Set as Background" (in Netscape) context menu on an image URL that is really a javascript: URL with an eval statement, aka "Firewalling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-04T08:55:00.000-04:00" comment="Updated reference to CVE-2005-2262 per Rob Hollis">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2005-10-11T04:20:00.000-04:00" comment="modified wrt-10045 - Removed doubled backslash from string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:56:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-10-07T09:14:04.694-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="true">
          <criterion comment="Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:259"/>
          <criterion comment="Mozilla Firefox version 1.0.2 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:258"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100010" version="1" class="vulnerability">
      <metadata>
        <title>Firefox InstallTrigger Callback Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2263" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2263"/>
        <description>The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-07T04:00:00.000-04:00" comment="Added description">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-09-28T01:05:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-19T05:47:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:53:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100009" version="1" class="vulnerability">
      <metadata>
        <title>Firefox Sidebar Script Injection via _search Target</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2264" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2264"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:52:00.000-04:00" comment="Added Firefox as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100008" version="1" class="vulnerability">
      <metadata>
        <title>InstallVersion.compareTo() DoS and Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2265" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2265"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and crash), and possibly execute arbitrary code, by calling InstallVersion.compareTo with an object instead of a string.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:51:00.000-04:00" comment="Added Mozilla and Firefox as affected products.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100007" version="1" class="vulnerability">
      <metadata>
        <title>Firefox and Mozilla Framed Site Spoofing Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1937" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1937"/>
        <description>A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-09-22T09:45:00.000-04:00" comment="Added CVE#">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:49:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100006" version="1" class="vulnerability">
      <metadata>
        <title>Firefox External App Code Acceptance Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Firefox</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2267" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2267"/>
        <description>Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash and QuickTime to open a javascript: URL, which is run in the context of the previous page, and may lead to code execution if the standalone application loads a privileged chrome: URL.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-07T04:00:00.000-04:00" comment="Added description">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-08T01:14:00.000-04:00" comment="Removed test for Mozilla Suite 1.7.8.  Per Rob Hollis &amp;#60;rob@threatguard.com> this definition should not have tested for Mozilla Suite; only Firefox is vulnerable.  Vendor advisory agrees.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:47:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <modified date="2006-02-01T05:47:00.000-04:00" comment="Changed affected product to Firefox.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100005" version="1" class="vulnerability">
      <metadata>
        <title>Firefox and Mozilla Javascript Dialog Box Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2268" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2268"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-07T04:00:00.000-04:00" comment="Added Description">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <modified date="2005-10-04T08:47:00.000-04:00" comment="Changed CVE reference to CAN-2005-2268, per Rob Hollis">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-19T05:47:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:45:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100004" version="1" class="vulnerability">
      <metadata>
        <title>Firefox and Mozilla DOM Node Spoofing</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2269" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2269"/>
        <description>Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-02-01T04:43:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-01T09:07:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100003" version="1" class="vulnerability">
      <metadata>
        <title>Firefox and Mozilla Shared Object Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2270" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2270"/>
        <description>Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10048 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <status_change date="2005-12-12T09:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-12-28T04:28:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-01-25T04:02:00.000-04:00" comment="Added Mozilla as affected product.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-01-25T07:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Mozilla Firefox version 1.0.4 or earlier is installed">
          <criterion comment="Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:263"/>
          <criterion comment="Mozilla Firefox version 1.0.4 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:262"/>
        </criteria>
        <criteria operator="AND" comment="Mozilla Suite version 1.7.8 or earlier is installed">
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:261"/>
          <criterion comment="Mozilla Suite version 1.7.8 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:260"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100002" version="2" class="vulnerability">
      <metadata>
        <title>IFRAME in Firefox and Mozilla Permits Execution of Arbitrary Javascript in Other Domains</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1476" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1476"/>
        <description>Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10025 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:13:00.000-04:00" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-06T04:00:00.000-04:00" comment="Fixed ste:262 by properly anchoring the regular expression.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-06T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:55.097-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Firefox &lt;= 1.0.3 or Mozilla Suite &lt;= 1.7.7 is installed">
          <criterion comment="Firefox version 1.0.3 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:265"/>
          <criterion comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:100001" version="2" class="vulnerability">
      <metadata>
        <title>Install Function in Firefox and Mozilla Permits Arbitrary Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>mozilla</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1477" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1477"/>
        <description>The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-08-16T04:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <modified date="2005-09-19T04:00:00.000-04:00" comment="modified wrt-10025 - Removed extra \\ in key">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-10-05T11:37:00.000-04:00">INTERIM</status_change>
            <modified date="2005-10-11T04:13:00.000-04:00" comment="modified wrt-10024 - Removed doubled backslashes in string literal test.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2005-10-26T06:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-06T04:00:00.000-04:00" comment="Fixed ste:262 by properly anchoring the regular expression.  Modified by Harvey Rubinovitz">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-06T11:37:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:53.777-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="Firefox &lt;= 1.0.3 or Mozilla Suite &lt;= 1.7.7 is installed">
          <criterion comment="Firefox version 1.0.3 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:265"/>
          <criterion comment="Mozilla Suite version 1.7.7 or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1000" version="2" class="vulnerability">
      <metadata>
        <title>Windows XP Help Center Command Insertion Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Help and Support Center (HSC)</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0907" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0907"/>
        <description>Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-04-14T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </submitted>
            <status_change date="2004-04-14T12:00:00.000-04:00">DRAFT</status_change>
            <modified date="2004-05-12T12:00:00.000-04:00" comment="Added a criterion to the configuration section to see if the HCP protocol is registered.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2004-06-16T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-30T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-13T11:23:00.000-04:00" comment="cmp-66 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1001 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-30T12:00:00.000-04:00" comment="negated the criterion for a service pack is installed to reflect that NO service pack is installed">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-09-27T12:28:14.997-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="a vulnerable version of helpctr.exe exists on XP">
            <criteria operator="AND" comment="No service pack is installed, 32 bit Edition, and helpctr.exe is less than 5.1.2600.128">
              <criterion comment="a Win2K/XP/2003 service pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
              <criterion comment="32-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2748"/>
              <criterion comment="the version of helpctr.exe is less than 5.1.2600.128" negate="false" test_ref="oval:org.mitre.oval:tst:1333"/>
            </criteria>
            <criteria operator="AND" comment="Affected helpctr.exe versions on Windows XP SP1">
              <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
              <criterion comment="the version of helpctr.exe is less than 5.1.2600.1340" negate="false" test_ref="oval:org.mitre.oval:tst:1332"/>
            </criteria>
          </criteria>
          <criterion comment="the patch kb835732 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1510"/>
          <criteria operator="AND" comment="Windows XP (sp1 or earlier) is installed">
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
          </criteria>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="the HCP Protocol is registered" negate="true" test_ref="oval:org.mitre.oval:tst:1477"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:565" version="2">
      <metadata>
        <title>Microsoft Windows Server 2003, SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows Server 2003, SP1.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:31.197-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:44.696-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:563" version="2">
      <metadata>
        <title>Internet Explorer 6 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Internet Explorer 6 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:31.086-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:44.500-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:521" version="2">
      <metadata>
        <title>Microsoft Windows XP, SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows XP, SP2.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:29.930-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:43.496-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
        <criterion comment="Win2K/XP/2003 service pack 2 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2837"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:480" version="2">
      <metadata>
        <title>Microsoft Windows XP, SP1 (64-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows XP, SP1 (64-bit).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:28.342-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:42.090-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
        <criterion comment="64-Bit version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:325" version="2">
      <metadata>
        <title>Internet Explorer 5.01,SP4 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The application Microsoft Internet Explorer 5.01,SP4 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-08-11T12:53:40">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-08T11:26:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:20.990-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:38.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Internet Explorer 6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2794"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:85" version="1">
      <metadata>
        <title>Microsoft Windows 2000 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows 2000.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows 2000 is installed" test_ref="oval:org.mitre.oval:tst:2"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:229" version="2">
      <metadata>
        <title>Microsoft Windows 2000, SP4 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows 2000, SP4.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:29:16.978-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:58:35.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows 2000 is installed" definition_ref="oval:org.mitre.oval:def:85"/>
        <criterion comment="SP4 or later is installed" test_ref="oval:org.mitre.oval:tst:3073"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:128" version="1">
      <metadata>
        <title>Microsoft Windows Server 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows Server 2003.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows Server 2003 is installed" test_ref="oval:org.mitre.oval:tst:4"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:165" version="2">
      <metadata>
        <title>Microsoft Windows Server 2003 (Gold) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows Server 2003 (Gold).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:51.952-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:23.741-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows Server 2003 is installed" definition_ref="oval:org.mitre.oval:def:128"/>
        <criterion comment="a Windows 2000/XP/2003 Service Pack is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2845"/>
      </criteria>
    </definition>
    <definition class="vulnerability" id="oval:org.mitre.oval:def:100" version="2">
      <metadata>
        <title>VML Buffer Overrun Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Internet Explorer</product>
        </affected>
        <reference ref_id="CVE-2006-4868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4868" source="CVE"/>
        <description>Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-27T04:20:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-29T22:14:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-16T15:57:18.418-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:27.997-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.3790.593" negate="false" test_ref="oval:org.mitre.oval:tst:124"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.3790.2794" negate="false" test_ref="oval:org.mitre.oval:tst:10"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of vgx.dll is less than 6.0.2900.2997" negate="false" test_ref="oval:org.mitre.oval:tst:93"/>
        </criteria>
        <criteria comment="IE 6 on Windows 2000 or XP,SP1 (32-bit)" operator="AND">
          <criteria operator="OR" comment="Win2K,SP4 or XP,SP1 (32-bit) is installed">
            <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
            <extend_definition comment="Windows XP, SP1 is installed" definition_ref="oval:org.mitre.oval:def:1"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="Internet Explorer 6 (any patch level) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2333"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.2800.1580" negate="false" test_ref="oval:org.mitre.oval:tst:25"/>
        </criteria>
        <criteria comment="IE 5.01,SP4 on Win2k,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Internet Explorer 5.01, SP4 is installed" definition_ref="oval:org.mitre.oval:def:325"/>
          <criterion comment="the version of mshtml.dll is less than 5.0.3845.1800" negate="false" test_ref="oval:org.mitre.oval:tst:163"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:10" version="1" class="vulnerability">
      <metadata>
        <title>Heap Overflow in Solaris 8 xlock</title>
        <affected family="unix">
          <platform>Sun Solaris 8</platform>
          <product>xlock</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0652" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0652"/>
        <description>Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPATH or (2) XUSERFILESEARCHPATH environmental variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2002-09-17T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">David Proulx</contributor>
            </submitted>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Solaris 8 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:3145"/>
          <criterion comment="File xlock exists" negate="false" test_ref="oval:org.mitre.oval:tst:3130"/>
          <criterion comment="Patch 108652-38 or later installed" negate="true" test_ref="oval:org.mitre.oval:tst:3129"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criteria operator="AND" comment="File xlock SUID and executable">
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3128"/>
            <criterion comment="File xlock SUID and executable" negate="false" test_ref="oval:org.mitre.oval:tst:3127"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:105" version="1">
      <metadata>
        <title>Microsoft Windows XP is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows XP.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-26T12:55:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2006-06-26T12:55:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="the installed operating system is part of the Microsoft Windows family" test_ref="oval:org.mitre.oval:tst:99"/>
        <criterion comment="Windows XP is installed" test_ref="oval:org.mitre.oval:tst:3"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:1" version="2">
      <metadata>
        <title>Microsoft Windows XP, SP1 (32-bit) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows XP, SP1 (32-bit).</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-07-27T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-09-27T12:28:14.071-04:00">INTERIM</status_change>
            <status_change date="2006-10-16T15:57:17.080-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Windows XP is installed" definition_ref="oval:org.mitre.oval:def:105"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Win2K/XP/2003 service pack 1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2843"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <registry_test id="oval:org.mitre.oval:tst:1602" version="1" check="at least one" comment="Windows Media Services 4.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1078"/>
      <state state_ref="oval:org.mitre.oval:ste:1454"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1601" version="1" check="at least one" comment="the version of nscm.exe is less than 4.1.0.3934" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1077"/>
      <state state_ref="oval:org.mitre.oval:ste:1453"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1600" version="1" check="at least one" comment="the version of nspmon.exe is less than 4.1.0.3934" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1076"/>
      <state state_ref="oval:org.mitre.oval:ste:1452"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1599" version="1" check="at least one" comment="the patch kb832359 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1075"/>
      <state state_ref="oval:org.mitre.oval:ste:1451"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:1598" version="1" comment="configured to only offer streaming media over unicast" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <registry_test id="oval:org.mitre.oval:tst:1597" version="1" check="at least one" comment="the Windows Media Station service is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1074"/>
      <state state_ref="oval:org.mitre.oval:ste:1450"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1596" version="1" check="at least one" comment="the Windows Media Monitor service is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1073"/>
      <state state_ref="oval:org.mitre.oval:ste:1449"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2379" version="1" check="at least one" comment="SharePoint Team Services are enabled (2K, XP, 2003)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1361"/>
      <state state_ref="oval:org.mitre.oval:ste:2228"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:2435" version="1" comment="Excel 97 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test id="oval:org.mitre.oval:tst:2434" version="2" check="at least one" comment="the version of excel.exe is less than 8.00.01.9904" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2280"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:2490" version="1" comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test id="oval:org.mitre.oval:tst:73" version="1" check="at least one" comment="the version of wkssvc.dll is less than 5.0.2195.7108" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1448"/>
      <state state_ref="oval:org.mitre.oval:ste:50"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:113" version="1" check="at least one" comment="the version of wkssvc.dll is less than 5.1.2600.2976" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1448"/>
      <state state_ref="oval:org.mitre.oval:ste:54"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:2529" version="1" comment="Word 98 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test id="oval:org.mitre.oval:tst:2528" version="2" check="at least one" comment="the version of winword.exe is less than 8.0.0.9716" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2365"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:2531" version="1" comment="Word 97 is installed" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</oval-def:note>
      </oval-def:notes>
    </unknown_test>
    <file_test id="oval:org.mitre.oval:tst:2530" version="1" check="at least one" comment="the version of winword.exe is less than 8.0.0.9315" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2366"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:137" version="1" check="at least one" comment="the version of Sxs.dll is less than 5.1.2600.3019" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:336"/>
      <state state_ref="oval:org.mitre.oval:ste:164"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:123" version="1" check="at least one" comment="the version of Sxs.dll is less than 5.2.3790.599" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:336"/>
      <state state_ref="oval:org.mitre.oval:ste:113"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:96" version="1" check="at least one" comment="the version of dxmasf.dll is less than 6.4.9.1133" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1568"/>
      <state state_ref="oval:org.mitre.oval:ste:83"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:191" version="1" check="at least one" comment="the version of Wmvcore.dll is less than 10.0.0.3702" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:91"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:174" version="1" check="at least one" comment="the version of Wmvcore.dll is less than 7.10.0.3079" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:80"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:125" version="1" check="at least one" comment="Wmvcore.dll for Windows Media Format 9.0 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:78"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:117" version="1" check="at least one" comment="the version of Wmvcore.dll is less than 10.0.0.3810" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:79"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:116" version="1" check="at least one" comment="the version of Wmvcore.dll is less than 10.0.0.3708" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:140"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:115" version="1" check="at least one" comment="Wmvcore.dll for Windows Media Format 9.5 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:172"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:112" version="1" check="at least one" comment="the version of Wmvcore.dll is less than 9.0.0.3265" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:112"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:102" version="1" check="at least one" comment="Wmvcore.dll for Windows Media Format 7.1 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:52"/>
      <state state_ref="oval:org.mitre.oval:ste:76"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:100" version="1" check="at least one" comment="Media Player 8 (v6.4) is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6"/>
      <state state_ref="oval:org.mitre.oval:ste:108"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2605" version="1" check="at least one" comment="the version of exprox.dll is less than 6.5.6980.57" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1481"/>
      <state state_ref="oval:org.mitre.oval:ste:2434"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2604" version="1" check="at least one" comment="the patch KB832759 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1480"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:2603" version="1" comment="this is a front-end server providing Outlook Web Access" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <unknown_test id="oval:org.mitre.oval:tst:2602" version="1" comment="the back-end server is Exchange Server 2003 running on Windows 2003" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <registry_test id="oval:org.mitre.oval:tst:2601" version="1" check="at least one" comment="HTTP connection reuse is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1479"/>
      <state state_ref="oval:org.mitre.oval:ste:2433"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:2600" version="1" comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test check="all" comment="the version of Aspnet_filter.dll is less than 2.0.50727.101" id="oval:org.mitre.oval:tst:8" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:180"/>
      <state state_ref="oval:org.mitre.oval:ste:98"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:84" version="1" check="at least one" comment="The version of nwrdr.sys is less than 5.2.3790.588" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:5"/>
      <state state_ref="oval:org.mitre.oval:ste:118"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:76" version="1" check="at least one" comment="The version of nwrdr.sys is less than 5.2.3790.2783" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:5"/>
      <state state_ref="oval:org.mitre.oval:ste:58"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:75" version="1" check="at least one" comment="The version of nwrdr.sys is less than 5.1.2600.3015" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:5"/>
      <state state_ref="oval:org.mitre.oval:ste:145"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:74" version="1" check="at least one" comment="The version of nwrdr.sys is less than 5.0.2195.7110" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:5"/>
      <state state_ref="oval:org.mitre.oval:ste:55"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:197" version="1" check="at least one" comment="The RIS Server has been set to prevent unauthorized access." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:7"/>
      <state state_ref="oval:org.mitre.oval:ste:181"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:177" version="1" check="at least one" comment="TFTP Service is activated." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:93"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:426" version="1" check="at least one" comment="Patch 113073-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:376"/>
      <state state_ref="oval:org.mitre.oval:ste:393"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:425" version="1" check="at least one" comment="Solaris Volume Manager package installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:375"/>
    </package_test>
    <file_test id="oval:org.mitre.oval:tst:424" version="1" check="at least one" comment="svm.init init script exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:374"/>
    </file_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:423" version="2" check="all" comment="/etc/vfstab is configured with SVM devices" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:373"/>
    </textfilecontent_test>
    <file_test id="oval:org.mitre.oval:tst:88" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3846.2300" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:155"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:149" version="1" check="at least one" comment="Microsoft Visual Studio 2005 is Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:8"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:150" version="1" check="at least one" comment="the version of WmiScriptUtils.dll is less than 8.0.50727.236" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:38"/>
      <state state_ref="oval:org.mitre.oval:ste:93"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:595" version="1" check="at least one" comment="the patch q841373 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:497"/>
      <state state_ref="oval:org.mitre.oval:ste:539"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:594" version="1" check="at least one" comment="the version of w3svc.dll is less than 4.2.788.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:496"/>
      <state state_ref="oval:org.mitre.oval:ste:538"/>
    </file_test>
    <metabase_test id="oval:org.mitre.oval:tst:593" version="1" check="at least one" comment="Permanent redirects enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:495"/>
      <state state_ref="oval:org.mitre.oval:ste:537"/>
    </metabase_test>
    <registry_test id="oval:org.mitre.oval:tst:592" version="2" check="at least one" comment="MaxClientRequestBufferData less than or equal to 16384" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:494"/>
      <state state_ref="oval:org.mitre.oval:ste:536"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:839" version="2" check="at least one" comment="The version of Ntkrnlpa.exe is less than 5.0.2195.7071" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:633"/>
      <state state_ref="oval:org.mitre.oval:ste:752"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:195" version="1" check="at least one" comment="the version of agentdpv.dll is less than 2.0.0.3424" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1000"/>
      <state state_ref="oval:org.mitre.oval:ste:95"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:109" version="1" check="at least one" comment="the version of agentdpv.dll is less than 5.2.3790.1242" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1000"/>
      <state state_ref="oval:org.mitre.oval:ste:70"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:939" version="1" check="at least one" comment="File /usr/dt/bin/dtlogin exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:703"/>
    </file_test>
    <process_test id="oval:org.mitre.oval:tst:938" version="1" check="at least one" comment="dtlogin running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:702"/>
    </process_test>
    <patch_test id="oval:org.mitre.oval:tst:937" version="3" check="at least one" comment="Patch 108919-21 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:701"/>
      <state state_ref="oval:org.mitre.oval:ste:841"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:936" version="1" check="at least one" comment="Patch 112807-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:700"/>
      <state state_ref="oval:org.mitre.oval:ste:840"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:935" version="1" check="at least one" comment="Patch 107180-31 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:699"/>
      <state state_ref="oval:org.mitre.oval:ste:839"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:1024" version="1" check="at least one" comment="System and Network Administration Framework Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:752"/>
    </package_test>
    <inetd_test id="oval:org.mitre.oval:tst:1023" version="1" check="at least one" comment="inetd.conf contains sadmind" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:751"/>
      <state state_ref="oval:org.mitre.oval:ste:913"/>
    </inetd_test>
    <patch_test id="oval:org.mitre.oval:tst:1022" version="1" check="at least one" comment="Patch 116457-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:750"/>
      <state state_ref="oval:org.mitre.oval:ste:912"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1021" version="1" check="at least one" comment="Patch 116442-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:749"/>
      <state state_ref="oval:org.mitre.oval:ste:911"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1020" version="2" check="at least one" comment="Patch 116454-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:748"/>
      <state state_ref="oval:org.mitre.oval:ste:910"/>
    </patch_test>
    <inetd_test id="oval:org.mitre.oval:tst:1019" version="1" check="at least one" comment="Sadmin called using strong authentication" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:747"/>
      <state state_ref="oval:org.mitre.oval:ste:909"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:92" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.605" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:74"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:90" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2817" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:69"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:89" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1586" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:63"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:132" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.3020" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:67"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:71" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.594" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:57"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:70" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2795" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:101"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:66" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2995" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:97"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:65" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1578" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:177"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:142" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3842.3000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:49"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:148" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.3790.607" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:90"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:146" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.3790.2826" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:89"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:145" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2900.3028" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:134"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:143" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2800.1896" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:88"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:134" version="1" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4971.600" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:87"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:85" version="1" check="at least one" comment="the version of Flash9.ocx is greater than or equal 9.0.16.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:17"/>
      <state state_ref="oval:org.mitre.oval:ste:61"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:83" version="1" check="at least one" comment="the version of Flash8.ocx is greater than or equal 8.0.22.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:80"/>
      <state state_ref="oval:org.mitre.oval:ste:59"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:79" version="1" check="at least one" comment="Flash.ocx exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:648"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:121" version="1" check="at least one" comment="the version of snmp.exe is less than 5.2.3790.615" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:86"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:120" version="1" check="at least one" comment="the version of snmp.exe is less than 5.2.3790.2837" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:84"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:119" version="1" check="at least one" comment="the version of snmp.exe is less than 5.1.2600.3038" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:103"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:118" version="1" check="at least one" comment="the version of snmp.exe is less than 5.0.2195.7112" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:82"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:62" version="1" check="at least one" comment="The version of Msxml4.dll is less than 4.20.9841.0." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:191"/>
      <state state_ref="oval:org.mitre.oval:ste:117"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:138" version="1" check="at least one" comment="The version of Msxml6.dll is less than 6.0.3890.0." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:190"/>
      <state state_ref="oval:org.mitre.oval:ste:48"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:1271" version="1" comment="Affected bkupexec.exe versions 3.60.1.298" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>We think, but are not sure that the affected version of bkupexec.exe is 3.60.1.298 The file should be found in C:\Program Files\VERITAS\Backup Exec\NT\bkupexec.exe</oval-def:note>
      </oval-def:notes>
    </unknown_test>
    <registry_test id="oval:org.mitre.oval:tst:1270" version="1" check="at least one" comment="Veritas Backup Exec 8.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:885"/>
      <state state_ref="oval:org.mitre.oval:ste:1140"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1269" version="1" check="at least one" comment="RestrictAnonymous registry value allows anonymous connections" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:884"/>
      <state state_ref="oval:org.mitre.oval:ste:1139"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:1403" version="1" comment="machine has followed the GDR update path and rpcss.dll is less than 5.2.3790.132" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <unknown_test id="oval:org.mitre.oval:tst:1402" version="1" comment="machine has followed the QFE update path and rpcss.dll is less than 5.2.3790.142" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test id="oval:org.mitre.oval:tst:1401" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.2.3790.142" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:1263"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:1498" version="1" comment="machine has followed the GDR update path and rpcrt4.dll is less than 5.2.3790.137" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <unknown_test id="oval:org.mitre.oval:tst:1497" version="1" comment="machine has followed the QFE update path and rpcrt4.dll is less than 5.2.3790.141" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <unknown_test id="oval:org.mitre.oval:tst:340" version="1" comment="Service Pack 2 or less for Windows Office XP" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>Service Pack 2 or less for Windows Office XP needs regex involving strings and less than</oval-def:note>
      </oval-def:notes>
    </unknown_test>
    <unknown_test id="oval:org.mitre.oval:tst:393" version="1" comment="Sendmail has recipient or final rulesets" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>egrep "^[Srecipient=2|S2]|^[^#]*\$>2|^[^#]*\$>recipient|^[^#]*\$>4|^[^#]*\$>final" /etc/mail/sendmail.cf True if any lines returned</oval-def:note>
      </oval-def:notes>
    </unknown_test>
    <patch_test id="oval:org.mitre.oval:tst:392" version="1" check="at least one" comment="Patch 107684-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:351"/>
      <state state_ref="oval:org.mitre.oval:ste:368"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:391" version="1" check="at least one" comment="Patch 110615-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:350"/>
      <state state_ref="oval:org.mitre.oval:ste:367"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:497" version="1" check="all" comment="Patch 112604-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:427"/>
      <state state_ref="oval:org.mitre.oval:ste:456"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:496" version="1" check="all" comment="Patch 112609-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:426"/>
      <state state_ref="oval:org.mitre.oval:ste:455"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:495" version="1" check="all" comment="Patch 115172-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:425"/>
      <state state_ref="oval:org.mitre.oval:ste:454"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:494" version="1" check="all" comment="Lance Ethernet (le) interface configured to start" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:424"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:493" version="1" comment="Lance Ethernet interface in use" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note/>
      </oval-def:notes>
    </unknown_test>
    <patch_test id="oval:org.mitre.oval:tst:542" version="1" check="at least one" comment="Patch 106541-33 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:291"/>
      <state state_ref="oval:org.mitre.oval:ste:491"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:541" version="1" check="at least one" comment="Patch 109007-18 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:458"/>
      <state state_ref="oval:org.mitre.oval:ste:490"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:540" version="1" check="at least one" comment="Patch 114332-12 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:361"/>
      <state state_ref="oval:org.mitre.oval:ste:489"/>
    </patch_test>
    <unknown_test id="oval:org.mitre.oval:tst:539" version="1" comment="Basic Security Module enabled" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>grep c2audit /etc/system True if "set c2audit:audit_load = 1" or similiar</oval-def:note>
      </oval-def:notes>
    </unknown_test>
    <unknown_test id="oval:org.mitre.oval:tst:538" version="1" comment="Auditing Administrative or System-Wide Administrative audit classes" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>egrep ^flags:.*a[sd] /etc/security/audit_control True if any lines returned</oval-def:note>
      </oval-def:notes>
    </unknown_test>
    <file_test id="oval:org.mitre.oval:tst:1113" version="1" check="at least one" comment="the version of CrystalDecisions.Web.dll is less than 9.1.9800.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:806"/>
      <state state_ref="oval:org.mitre.oval:ste:994"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1112" version="1" check="at least one" comment="the w3svc service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:805"/>
      <state state_ref="oval:org.mitre.oval:ste:993"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:1111" version="1" comment="a website linked to the Crystal Reports Viewer is active" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <patch_test id="oval:org.mitre.oval:tst:1337" version="1" check="at least one" comment="Patch 118908-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:925"/>
      <state state_ref="oval:org.mitre.oval:ste:1199"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1335" version="1" check="at least one" comment="Patch 118966-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:581"/>
      <state state_ref="oval:org.mitre.oval:ste:1198"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:1334" version="1" check="at least one" comment="The Xorg X server is running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:923"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:1341" version="1" check="at least one" comment="/proc/tty/driver/serial is world-readable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:929"/>
      <state state_ref="oval:org.mitre.oval:ste:1203"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1340" version="1" check="at least one" comment="/proc/tty/driver/ is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:928"/>
      <state state_ref="oval:org.mitre.oval:ste:1202"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1339" version="1" check="at least one" comment="/proc/tty/ is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:927"/>
      <state state_ref="oval:org.mitre.oval:ste:1201"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1338" version="1" check="at least one" comment="/proc/ is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:926"/>
      <state state_ref="oval:org.mitre.oval:ste:1200"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1344" version="1" check="at least one" comment="File %windir%\system\vserver.vxd version is less than 4.10.2001.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:932"/>
      <state state_ref="oval:org.mitre.oval:ste:1206"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1343" version="1" check="at least one" comment="Patch 273991USA8.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:931"/>
      <state state_ref="oval:org.mitre.oval:ste:1205"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1346" version="1" check="at least one" comment="the version of rpcproxy.dll is less than 5.0.2195.6904" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:887"/>
      <state state_ref="oval:org.mitre.oval:ste:1208"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:1350" version="1" check="at least one" comment="OS-Core.CORE2-KRN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:936"/>
      <state state_ref="oval:org.mitre.oval:ste:1212"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1349" version="1" check="at least one" comment="Patch PHKL_33713 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:935"/>
      <state state_ref="oval:org.mitre.oval:ste:1211"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1348" version="1" check="at least one" comment="Patch PHKL_33714 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:934"/>
      <state state_ref="oval:org.mitre.oval:ste:1210"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1351" version="1" check="at least one" comment="krb5-libs rpm version prior to 1.2.7-24 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:937"/>
      <state state_ref="oval:org.mitre.oval:ste:1213"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1352" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.00.2739.300" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1214"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1354" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2800.1506" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1216"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1359" version="1" check="at least one" comment="ethereal version is less than 0.10.3-0.30E.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:940"/>
      <state state_ref="oval:org.mitre.oval:ste:1221"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1358" version="1" check="at least one" comment="ethereal-gnome version is less than 0.10.3-0.30E.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:939"/>
      <state state_ref="oval:org.mitre.oval:ste:1220"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1361" version="1" check="at least one" comment="squid version is less than 2.5.STABLE3-6.3E" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:942"/>
      <state state_ref="oval:org.mitre.oval:ste:1223"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1360" version="1" check="at least one" comment="squid is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:941"/>
      <state state_ref="oval:org.mitre.oval:ste:1222"/>
    </inetlisteningservers_test>
    <file_test id="oval:org.mitre.oval:tst:2945" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2760"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2944" version="1" check="at least one" comment="Gopher Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1685"/>
      <state state_ref="oval:org.mitre.oval:ste:2759"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1366" version="1" check="at least one" comment="utempter version is less than 0.5.5-1.3EL.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:944"/>
      <state state_ref="oval:org.mitre.oval:ste:1228"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1365" version="1" check="at least one" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:943"/>
      <state state_ref="oval:org.mitre.oval:ste:1227"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1364" version="1" check="at least one" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:943"/>
      <state state_ref="oval:org.mitre.oval:ste:1226"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1363" version="1" check="at least one" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:943"/>
      <state state_ref="oval:org.mitre.oval:ste:1225"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1362" version="1" check="at least one" comment="/usr/sbin/utempter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:943"/>
      <state state_ref="oval:org.mitre.oval:ste:1224"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1370" version="1" check="at least one" comment="lha version is less than 1.14i-10.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:946"/>
      <state state_ref="oval:org.mitre.oval:ste:1232"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1369" version="1" check="at least one" comment="/usr/bin/lha is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:945"/>
      <state state_ref="oval:org.mitre.oval:ste:1231"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1368" version="1" check="at least one" comment="/usr/bin/lha is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:945"/>
      <state state_ref="oval:org.mitre.oval:ste:1230"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1367" version="1" check="at least one" comment="/usr/bin/lha is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:945"/>
      <state state_ref="oval:org.mitre.oval:ste:1229"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1374" version="1" check="at least one" comment="tcpdump version is less than 3.7.2-7.E3.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:948"/>
      <state state_ref="oval:org.mitre.oval:ste:1236"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1373" version="1" check="at least one" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:947"/>
      <state state_ref="oval:org.mitre.oval:ste:1235"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1372" version="1" check="at least one" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:947"/>
      <state state_ref="oval:org.mitre.oval:ste:1234"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1371" version="1" check="at least one" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:947"/>
      <state state_ref="oval:org.mitre.oval:ste:1233"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1378" version="1" check="at least one" comment="libpng version is less than 1.2.2-21" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:952"/>
      <state state_ref="oval:org.mitre.oval:ste:1240"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1377" version="1" check="at least one" comment="libpng-devel version is less than 1.2.2-21" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:951"/>
      <state state_ref="oval:org.mitre.oval:ste:1239"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1376" version="1" check="at least one" comment="libpng10 version is less than 1.0.13-12" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:950"/>
      <state state_ref="oval:org.mitre.oval:ste:1238"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1375" version="1" check="at least one" comment="libpng10-devel version is less than 1.0.13-12" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:949"/>
      <state state_ref="oval:org.mitre.oval:ste:1237"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1382" version="1" check="at least one" comment="cvs version is less than 1.11.2-22" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:954"/>
      <state state_ref="oval:org.mitre.oval:ste:1244"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1385" version="1" check="at least one" comment="the version of rpcproxy.dll is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:887"/>
      <state state_ref="oval:org.mitre.oval:ste:1247"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1384" version="1" check="at least one" comment="the version of rpcproxy.dll is less than 4.0.1381.33559" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:887"/>
      <state state_ref="oval:org.mitre.oval:ste:1246"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1388" version="1" check="at least one" comment="the version of msjet40.dll is less than 4.0.8618.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:958"/>
      <state state_ref="oval:org.mitre.oval:ste:1250"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1387" version="1" check="at least one" comment="the version of wmsjet40.dll is less than 4.0.8618.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:957"/>
      <state state_ref="oval:org.mitre.oval:ste:1249"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1386" version="1" check="at least one" comment="the patch kb837001 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:956"/>
      <state state_ref="oval:org.mitre.oval:ste:1248"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1389" version="1" check="at least one" comment="rsync version is less than 2.5.7-4.3E" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:959"/>
      <state state_ref="oval:org.mitre.oval:ste:1251"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1390" version="1" check="at least one" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3861" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:960"/>
      <state state_ref="oval:org.mitre.oval:ste:1252"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1392" version="1" check="at least one" comment="the version of h323.tsp is less than 5.1.2600.134" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:961"/>
      <state state_ref="oval:org.mitre.oval:ste:1254"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1391" version="1" check="at least one" comment="the version of h323.tsp is less than 5.1.2600.1348" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:961"/>
      <state state_ref="oval:org.mitre.oval:ste:1253"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1394" version="1" check="at least one" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:1256"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1393" version="1" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 2000.80.746.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:1255"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1396" version="1" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:1258"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1397" version="1" check="all" comment="ImageMagick RPM earlier than 0:5.5.6-15" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <oval-def:notes>
        <oval-def:note>The ImageMagick-* RPMs all require that the main ImageMagick RPM have the same version and release number.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:963"/>
      <state state_ref="oval:org.mitre.oval:ste:1259"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2952" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2715.400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2767"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2950" version="1" check="at least one" comment="persistent cookies that are stored on your computer are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1690"/>
      <state state_ref="oval:org.mitre.oval:ste:2765"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2949" version="1" check="at least one" comment="persistent cookies that are stored on your computer are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1689"/>
      <state state_ref="oval:org.mitre.oval:ste:2764"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2948" version="1" check="at least one" comment="per-session cookies (not stored) are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1688"/>
      <state state_ref="oval:org.mitre.oval:ste:2763"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2947" version="1" check="at least one" comment="per-session cookies (not stored) are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1687"/>
      <state state_ref="oval:org.mitre.oval:ste:2762"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1398" version="1" check="at least one" comment="the version of mf3216.dll is less than 5.0.2195.6898" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:858"/>
      <state state_ref="oval:org.mitre.oval:ste:1260"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1400" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.1.2600.135" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:1262"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1399" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:1261"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1407" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.0.2195.6906" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:1266"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1426" version="1" check="at least one" comment="kdelibs version is less than 3.1.3-6.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:972"/>
      <state state_ref="oval:org.mitre.oval:ste:1285"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1425" version="1" check="at least one" comment="/usr/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:814"/>
      <state state_ref="oval:org.mitre.oval:ste:1284"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1424" version="1" check="at least one" comment="/usr/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:814"/>
      <state state_ref="oval:org.mitre.oval:ste:1283"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1423" version="1" check="at least one" comment="/usr/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:814"/>
      <state state_ref="oval:org.mitre.oval:ste:1282"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1422" version="1" check="at least one" comment="/usr/kerberos/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:971"/>
      <state state_ref="oval:org.mitre.oval:ste:1281"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1421" version="1" check="at least one" comment="/usr/kerberos/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:971"/>
      <state state_ref="oval:org.mitre.oval:ste:1280"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1420" version="1" check="at least one" comment="/usr/kerberos/bin/telnet is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:971"/>
      <state state_ref="oval:org.mitre.oval:ste:1279"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1419" version="1" check="at least one" comment="/usr/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:970"/>
      <state state_ref="oval:org.mitre.oval:ste:1278"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1418" version="1" check="at least one" comment="/usr/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:970"/>
      <state state_ref="oval:org.mitre.oval:ste:1277"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1417" version="1" check="at least one" comment="/usr/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:970"/>
      <state state_ref="oval:org.mitre.oval:ste:1276"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1416" version="1" check="at least one" comment="/usr/kerberos/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:969"/>
      <state state_ref="oval:org.mitre.oval:ste:1275"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1415" version="1" check="at least one" comment="/usr/kerberos/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:969"/>
      <state state_ref="oval:org.mitre.oval:ste:1274"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1414" version="1" check="at least one" comment="/usr/kerberos/bin/rlogin is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:969"/>
      <state state_ref="oval:org.mitre.oval:ste:1273"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1413" version="1" check="at least one" comment="/usr/bin/ssh is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:968"/>
      <state state_ref="oval:org.mitre.oval:ste:1272"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1412" version="1" check="at least one" comment="/usr/bin/ssh is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:968"/>
      <state state_ref="oval:org.mitre.oval:ste:1271"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1411" version="1" check="at least one" comment="/usr/bin/ssh is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:968"/>
      <state state_ref="oval:org.mitre.oval:ste:1270"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1410" version="1" check="at least one" comment="/usr/bin/kmail is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:967"/>
      <state state_ref="oval:org.mitre.oval:ste:1269"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1409" version="1" check="at least one" comment="/usr/bin/kmail is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:967"/>
      <state state_ref="oval:org.mitre.oval:ste:1268"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1408" version="1" check="at least one" comment="/usr/bin/kmail is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:967"/>
      <state state_ref="oval:org.mitre.oval:ste:1267"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1427" version="1" check="at least one" comment="File %windir%\system32\snmp.exe is less than 4.0.1381.133" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:1286"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1428" version="1" check="at least one" comment="the version of h323.tsp is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:961"/>
      <state state_ref="oval:org.mitre.oval:ste:1287"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1430" version="1" check="at least one" comment="ipsec-tools version is less than 0.2.5-0.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:975"/>
      <state state_ref="oval:org.mitre.oval:ste:1289"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1429" version="1" check="at least one" comment="racoon is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:974"/>
      <state state_ref="oval:org.mitre.oval:ste:1288"/>
    </inetlisteningservers_test>
    <patch_test id="oval:org.mitre.oval:tst:4130" version="1" check="at least one" comment="Patch 112785-50 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1996"/>
      <state state_ref="oval:org.mitre.oval:ste:3193"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3997" version="1" check="at least one" comment="Patch 119059-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2544"/>
      <state state_ref="oval:org.mitre.oval:ste:3924"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3963" version="1" check="at least one" comment="File Xsun SUID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2350"/>
      <state state_ref="oval:org.mitre.oval:ste:3519"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3558" version="1" check="at least one" comment="File Xprt SUID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1927"/>
      <state state_ref="oval:org.mitre.oval:ste:3222"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3529" version="1" check="at least one" comment="Patch 119060-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2024"/>
      <state state_ref="oval:org.mitre.oval:ste:3142"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3404" version="1" check="at least one" comment="Patch 112786-39 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2362"/>
      <state state_ref="oval:org.mitre.oval:ste:3016"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3400" version="1" check="at least one" comment="Patch 108652-93 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2405"/>
      <state state_ref="oval:org.mitre.oval:ste:3420"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3355" version="1" check="at least one" comment="Patch 108653-82 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2007"/>
      <state state_ref="oval:org.mitre.oval:ste:3126"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3178" version="1" check="at least one" comment="File Xsun SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2350"/>
      <state state_ref="oval:org.mitre.oval:ste:3943"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1431" version="1" check="at least one" comment="squid version is less than 2.5.STABLE3-5.3E" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:976"/>
      <state state_ref="oval:org.mitre.oval:ste:1290"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1433" version="1" check="at least one" comment="/bin/mount is world-executable AND Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:977"/>
      <state state_ref="oval:org.mitre.oval:ste:1292"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1432" version="1" check="at least one" comment="/bin/mount is world-executable AND Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:977"/>
      <state state_ref="oval:org.mitre.oval:ste:1291"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1436" version="1" check="at least one" comment="kernel version is less than 2.4.21-9.0.3.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:980"/>
      <state state_ref="oval:org.mitre.oval:ste:1295"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1435" version="1" check="at least one" comment="kernel-smp version is less than 2.4.21-9.0.3.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:979"/>
      <state state_ref="oval:org.mitre.oval:ste:1294"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1434" version="1" check="at least one" comment="kernel-hugemem version is less than 2.4.21-9.0.3.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:978"/>
      <state state_ref="oval:org.mitre.oval:ste:1293"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1437" version="1" check="at least one" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3932" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:960"/>
      <state state_ref="oval:org.mitre.oval:ste:1296"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1440" version="1" check="at least one" comment="File %windir%\System32\nsiislog.dll is less than 4.1.0.3931" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:960"/>
      <state state_ref="oval:org.mitre.oval:ste:1299"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1439" version="1" check="at least one" comment="Patch KB817772 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:982"/>
      <state state_ref="oval:org.mitre.oval:ste:1298"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1438" version="1" check="at least one" comment="Patch KB822343 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:981"/>
      <state state_ref="oval:org.mitre.oval:ste:1297"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1444" version="1" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 5.0.2195.6672" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:914"/>
      <state state_ref="oval:org.mitre.oval:ste:1302"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1443" version="1" check="at least one" comment="Patch Q811114 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:985"/>
      <state state_ref="oval:org.mitre.oval:ste:1301"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1446" version="1" check="at least one" comment="File %windir%\System32\code.asp is less than 4.0.1381.279" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:987"/>
      <state state_ref="oval:org.mitre.oval:ste:1304"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1445" version="1" check="at least one" comment="Patch Q232449 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:986"/>
      <state state_ref="oval:org.mitre.oval:ste:1303"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1448" version="1" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.2.780.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:914"/>
      <state state_ref="oval:org.mitre.oval:ste:1306"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1449" version="1" check="at least one" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4927.2100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1307"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1451" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2713.1100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1309"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1450" version="1" check="at least one" comment="Run ActiveX Controls and Plugins Allowed In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:988"/>
      <state state_ref="oval:org.mitre.oval:ste:1308"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1452" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.2.3790.139" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:1310"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1453" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2716.2200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1311"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1463" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4613.1700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1321"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1462" version="1" check="at least one" comment="Patch Q286045 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:995"/>
      <state state_ref="oval:org.mitre.oval:ste:1320"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1467" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.2.3790.134" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:1325"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1468" version="1" check="at least one" comment="mozilla-nss version is less than 1.4.2-3.0.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:996"/>
      <state state_ref="oval:org.mitre.oval:ste:1326"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1470" version="1" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.0.1381.164" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:997"/>
      <state state_ref="oval:org.mitre.oval:ste:1328"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1471" version="1" check="at least one" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.3649" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:998"/>
      <state state_ref="oval:org.mitre.oval:ste:1329"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1472" version="1" check="at least one" comment="the version of wintrust.dll is less than 5.131.1880.14" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:999"/>
      <state state_ref="oval:org.mitre.oval:ste:1330"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1473" version="1" check="all" comment="nwwks.dll is less than 5.2.3790.2506" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:652"/>
      <state state_ref="oval:org.mitre.oval:ste:1331"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1474" version="1" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.2.769.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:997"/>
      <state state_ref="oval:org.mitre.oval:ste:1332"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1475" version="1" check="at least one" comment="the version of h323.tsp is less than 5.0.2195.6901" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:961"/>
      <state state_ref="oval:org.mitre.oval:ste:1333"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1478" version="1" check="at least one" comment="the version of helpctr.exe is less than 5.2.3790.125" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:922"/>
      <state state_ref="oval:org.mitre.oval:ste:1335"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1479" version="1" check="at least one" comment="the version of schannel.dll is less than 4.87.1964.1880" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1002"/>
      <state state_ref="oval:org.mitre.oval:ste:1336"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1488" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.135" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:1345"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1487" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:1344"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2955" version="1" check="at least one" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:278"/>
      <state state_ref="oval:org.mitre.oval:ste:2770"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2954" version="1" check="at least one" comment="Patch Q291845 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1692"/>
      <state state_ref="oval:org.mitre.oval:ste:2769"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1490" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.134" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:1347"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1489" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.1361" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:1346"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1492" version="1" check="at least one" comment="the version of mf3216.dll is less than 4.0.1381.7263" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:858"/>
      <state state_ref="oval:org.mitre.oval:ste:1349"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1491" version="1" check="at least one" comment="the version of mf3216.dll is less than 4.0.1381.33562" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:858"/>
      <state state_ref="oval:org.mitre.oval:ste:1348"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1493" version="2" check="at least one" comment="the version of msgina.dll is less than 5.0.2195.6895" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:862"/>
      <state state_ref="oval:org.mitre.oval:ste:1350"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1496" version="1" check="at least one" comment="the version of msgina.dll is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:862"/>
      <state state_ref="oval:org.mitre.oval:ste:1353"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1495" version="1" check="at least one" comment="the version of msgina.dll is less than 4.0.1381.33559" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:862"/>
      <state state_ref="oval:org.mitre.oval:ste:1352"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1500" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.0.2195.6904" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:1355"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1501" version="1" check="at least one" comment="the version of schannel.dll is less than 5.1.2195.6899" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1002"/>
      <state state_ref="oval:org.mitre.oval:ste:1356"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1502" version="1" check="at least one" comment="the version of wintrust.dll is less than 5.131.2195.6824" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:999"/>
      <state state_ref="oval:org.mitre.oval:ste:1357"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2957" version="1" check="at least one" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1653"/>
      <state state_ref="oval:org.mitre.oval:ste:2772"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2956" version="1" check="at least one" comment="Patch Q311967 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1693"/>
      <state state_ref="oval:org.mitre.oval:ste:2771"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1505" version="1" check="at least one" comment="ethereal version is less than 0.10.3-0.30E.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1013"/>
      <state state_ref="oval:org.mitre.oval:ste:1360"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1504" version="1" check="at least one" comment="ethereal-gnome version is less than 0.10.3-0.30E.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1012"/>
      <state state_ref="oval:org.mitre.oval:ste:1359"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1507" version="1" check="at least one" comment="the version of schannel.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1002"/>
      <state state_ref="oval:org.mitre.oval:ste:1362"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1506" version="1" check="at least one" comment="the version of schannel.dll is less than 5.1.2600.1347" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1002"/>
      <state state_ref="oval:org.mitre.oval:ste:1361"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1513" version="1" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4939.300" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1367"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:1520" version="1" check="at least one" comment="Patch 109324-09 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:320"/>
      <state state_ref="oval:org.mitre.oval:ste:1374"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1519" version="1" check="at least one" comment="Patch 118535-03 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1021"/>
      <state state_ref="oval:org.mitre.oval:ste:1373"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1518" version="1" check="at least one" comment="Patch 121004-01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1020"/>
      <state state_ref="oval:org.mitre.oval:ste:1372"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1517" version="1" check="at least one" comment="Patch 109325-09 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1019"/>
      <state state_ref="oval:org.mitre.oval:ste:1371"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1516" version="1" check="at least one" comment="Patch 118536-03 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1018"/>
      <state state_ref="oval:org.mitre.oval:ste:1370"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1515" version="1" check="at least one" comment="Patch 121005-01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1017"/>
      <state state_ref="oval:org.mitre.oval:ste:1369"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1531" version="1" check="at least one" comment="ethereal version is less than 0.10.3-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1026"/>
      <state state_ref="oval:org.mitre.oval:ste:1385"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1530" version="1" check="at least one" comment="ethereal-gnome version is less than 0.10.3-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1025"/>
      <state state_ref="oval:org.mitre.oval:ste:1384"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1529" version="1" check="at least one" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1024"/>
      <state state_ref="oval:org.mitre.oval:ste:1383"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1528" version="1" check="at least one" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1024"/>
      <state state_ref="oval:org.mitre.oval:ste:1382"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1527" version="1" check="at least one" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1024"/>
      <state state_ref="oval:org.mitre.oval:ste:1381"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1526" version="1" check="at least one" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1023"/>
      <state state_ref="oval:org.mitre.oval:ste:1380"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1525" version="1" check="at least one" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1023"/>
      <state state_ref="oval:org.mitre.oval:ste:1379"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1524" version="1" check="at least one" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1023"/>
      <state state_ref="oval:org.mitre.oval:ste:1378"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1523" version="1" check="at least one" comment="/usr/bin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1022"/>
      <state state_ref="oval:org.mitre.oval:ste:1377"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1522" version="1" check="at least one" comment="/usr/bin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1022"/>
      <state state_ref="oval:org.mitre.oval:ste:1376"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1521" version="1" check="at least one" comment="/usr/bin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1022"/>
      <state state_ref="oval:org.mitre.oval:ste:1375"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1533" version="1" check="at least one" comment="squid version is less than 2.5STABLE1-3.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1028"/>
      <state state_ref="oval:org.mitre.oval:ste:1387"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1532" version="1" check="at least one" comment="squid is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1027"/>
      <state state_ref="oval:org.mitre.oval:ste:1386"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1534" version="1" check="at least one" comment="mod_ssl version is less than 2.0.46-32.ent" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1029"/>
      <state state_ref="oval:org.mitre.oval:ste:1388"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1538" version="1" check="at least one" comment="mozilla version is less than 1.4.2-0.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1031"/>
      <state state_ref="oval:org.mitre.oval:ste:1392"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1537" version="1" check="at least one" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1030"/>
      <state state_ref="oval:org.mitre.oval:ste:1391"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1536" version="1" check="at least one" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1030"/>
      <state state_ref="oval:org.mitre.oval:ste:1390"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1535" version="1" check="at least one" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1030"/>
      <state state_ref="oval:org.mitre.oval:ste:1389"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1539" version="1" check="at least one" comment="mozilla-nss version is less than 1.4.2-0.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1032"/>
      <state state_ref="oval:org.mitre.oval:ste:1393"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1543" version="1" check="at least one" comment="openssl version is less than 0.9.7a-33.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1036"/>
      <state state_ref="oval:org.mitre.oval:ste:1397"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1542" version="1" check="at least one" comment="openssl-devel version is less than 0.9.7a-33.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1035"/>
      <state state_ref="oval:org.mitre.oval:ste:1396"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1541" version="1" check="at least one" comment="openssl-perl version is less than 0.9.7a-33.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1034"/>
      <state state_ref="oval:org.mitre.oval:ste:1395"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1540" version="1" check="at least one" comment="openssl096b version is less than 0.9.6b-16" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1033"/>
      <state state_ref="oval:org.mitre.oval:ste:1394"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1545" version="1" check="at least one" comment="net-snmp version is less than 5.0.9-2.30E.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1038"/>
      <state state_ref="oval:org.mitre.oval:ste:1399"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1544" version="1" check="at least one" comment="snmpd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1037"/>
      <state state_ref="oval:org.mitre.oval:ste:1398"/>
    </inetlisteningservers_test>
    <uname_test id="oval:org.mitre.oval:tst:1547" version="1" check="at least one" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:1401"/>
    </uname_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1546" version="1" check="at least one" comment="kernel version is less than 2.4.21-9.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1039"/>
      <state state_ref="oval:org.mitre.oval:ste:1400"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1550" version="1" check="at least one" comment="kernel version is less than 2.4.21-4.0.2.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1042"/>
      <state state_ref="oval:org.mitre.oval:ste:1404"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1549" version="1" check="at least one" comment="kernel-smp version is less than 2.4.21-4.0.2.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1041"/>
      <state state_ref="oval:org.mitre.oval:ste:1403"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1548" version="1" check="at least one" comment="kernel-bigmem version is less than 2.4.21-4.0.2.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1040"/>
      <state state_ref="oval:org.mitre.oval:ste:1402"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1551" version="1" check="at least one" comment="cvs version is less than 1.11.2-14" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1043"/>
      <state state_ref="oval:org.mitre.oval:ste:1405"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1552" version="1" check="at least one" comment="kdepim version is less than 3.1.3-3.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1044"/>
      <state state_ref="oval:org.mitre.oval:ste:1406"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1553" version="1" check="at least one" comment="httpd version is less than 2.0.46-26.ent" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1045"/>
      <state state_ref="oval:org.mitre.oval:ste:1407"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1554" version="1" check="at least one" comment="httpd version is less than 2.0.40-21.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1046"/>
      <state state_ref="oval:org.mitre.oval:ste:1408"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1555" version="1" check="at least one" comment="sysstat version is less than 4.0.7-4.EL3.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1047"/>
      <state state_ref="oval:org.mitre.oval:ste:1409"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1557" version="1" check="at least one" comment="nfs-utils version is less than 1.0.6-7.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1049"/>
      <state state_ref="oval:org.mitre.oval:ste:1411"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1556" version="1" check="at least one" comment="rpc.mountd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1048"/>
      <state state_ref="oval:org.mitre.oval:ste:1410"/>
    </inetlisteningservers_test>
    <patch_test id="oval:org.mitre.oval:tst:2963" version="1" check="at least one" comment="Patch 108652-51 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:876"/>
      <state state_ref="oval:org.mitre.oval:ste:2778"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1560" version="1" check="at least one" comment="kernel version is less than 2.4.20-28.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1052"/>
      <state state_ref="oval:org.mitre.oval:ste:1414"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1559" version="1" check="at least one" comment="kernel-smp version is less than 2.4.20-28.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1051"/>
      <state state_ref="oval:org.mitre.oval:ste:1413"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1558" version="1" check="at least one" comment="kernel-bigmem version is less than 2.4.20-28.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1050"/>
      <state state_ref="oval:org.mitre.oval:ste:1412"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1564" version="1" check="at least one" comment="kdepim version is less than 3.1-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1054"/>
      <state state_ref="oval:org.mitre.oval:ste:1418"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1563" version="1" check="at least one" comment="/usr/share/services/kfile_vcf.desktop is readable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1053"/>
      <state state_ref="oval:org.mitre.oval:ste:1417"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1562" version="1" check="at least one" comment="/usr/share/services/kfile_vcf.desktop is readable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1053"/>
      <state state_ref="oval:org.mitre.oval:ste:1416"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1561" version="1" check="at least one" comment="/usr/share/services/kfile_vcf.desktop is readable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1053"/>
      <state state_ref="oval:org.mitre.oval:ste:1415"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1575" version="1" check="at least one" comment="ethereal version is less than 0.10.0a-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1057"/>
      <state state_ref="oval:org.mitre.oval:ste:1429"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1574" version="1" check="at least one" comment="ethereal-gnome version is less than 0.10.0a-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1056"/>
      <state state_ref="oval:org.mitre.oval:ste:1428"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1573" version="1" check="at least one" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1024"/>
      <state state_ref="oval:org.mitre.oval:ste:1427"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1572" version="1" check="at least one" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1024"/>
      <state state_ref="oval:org.mitre.oval:ste:1426"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1571" version="1" check="at least one" comment="/usr/bin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1024"/>
      <state state_ref="oval:org.mitre.oval:ste:1425"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1570" version="1" check="at least one" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1023"/>
      <state state_ref="oval:org.mitre.oval:ste:1424"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1569" version="1" check="at least one" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1023"/>
      <state state_ref="oval:org.mitre.oval:ste:1423"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1568" version="1" check="at least one" comment="/usr/sbin/ethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1023"/>
      <state state_ref="oval:org.mitre.oval:ste:1422"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1567" version="1" check="at least one" comment="/usr/sbin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1055"/>
      <state state_ref="oval:org.mitre.oval:ste:1421"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1566" version="1" check="at least one" comment="/usr/sbin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1055"/>
      <state state_ref="oval:org.mitre.oval:ste:1420"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1565" version="1" check="at least one" comment="/usr/sbin/tethereal is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1055"/>
      <state state_ref="oval:org.mitre.oval:ste:1419"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1577" version="1" check="at least one" comment="cvs version is less than 1.11.2-13" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1059"/>
      <state state_ref="oval:org.mitre.oval:ste:1431"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1576" version="1" check="at least one" comment="/ is world-writable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1058"/>
      <state state_ref="oval:org.mitre.oval:ste:1430"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1578" version="1" check="at least one" comment="tcpdump version is less than 3.7.2-7.E3.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1060"/>
      <state state_ref="oval:org.mitre.oval:ste:1432"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1579" version="1" check="at least one" comment="sysstat version is less than 4.0.7-4.rhl9.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1061"/>
      <state state_ref="oval:org.mitre.oval:ste:1433"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1583" version="1" check="at least one" comment="tcpdump version is less than 3.7.2-7.9.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1062"/>
      <state state_ref="oval:org.mitre.oval:ste:1437"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1582" version="1" check="at least one" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:947"/>
      <state state_ref="oval:org.mitre.oval:ste:1436"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1581" version="1" check="at least one" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:947"/>
      <state state_ref="oval:org.mitre.oval:ste:1435"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1580" version="1" check="at least one" comment="/usr/sbin/tcpdump is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:947"/>
      <state state_ref="oval:org.mitre.oval:ste:1434"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1586" version="1" check="at least one" comment="gdk-pixbuf version is less than 0.22.0-6.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1065"/>
      <state state_ref="oval:org.mitre.oval:ste:1440"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1585" version="1" check="at least one" comment="gdk-pixbuf-devel version is less than 0.22.0-6.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1064"/>
      <state state_ref="oval:org.mitre.oval:ste:1439"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1584" version="1" check="at least one" comment="gdk-pixbuf-gnome version is less than 0.22.0-6.1.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1063"/>
      <state state_ref="oval:org.mitre.oval:ste:1438"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1589" version="1" check="at least one" comment="gdk-pixbuf version is less than 0.22.0-6.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1068"/>
      <state state_ref="oval:org.mitre.oval:ste:1443"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1588" version="1" check="at least one" comment="gdk-pixbuf-devel version is less than 0.22.0-6.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1067"/>
      <state state_ref="oval:org.mitre.oval:ste:1442"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1587" version="1" check="at least one" comment="gdk-pixbuf-gnome version is less than 0.22.0-6.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1066"/>
      <state state_ref="oval:org.mitre.oval:ste:1441"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1591" version="1" check="at least one" comment="the version of msgsc.dll is greater than 6.0.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1069"/>
      <state state_ref="oval:org.mitre.oval:ste:1445"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1590" version="1" check="at least one" comment="the version of msgsc.dll is less than 6.1.0.211" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1069"/>
      <state state_ref="oval:org.mitre.oval:ste:1444"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1595" version="1" check="at least one" comment="Outlook 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1072"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1594" version="1" check="at least one" comment="the version of outlook.exe is less than 10.00.5709.0000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1070"/>
      <state state_ref="oval:org.mitre.oval:ste:1448"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1593" version="1" check="at least one" comment="the patch kb828040 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:334"/>
      <state state_ref="oval:org.mitre.oval:ste:1447"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1603" version="1" check="at least one" comment="mutt version is less than 1.4.1-3.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1079"/>
      <state state_ref="oval:org.mitre.oval:ste:1455"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1606" version="1" check="at least one" comment="kernel version is less than 2.4.20-30.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1082"/>
      <state state_ref="oval:org.mitre.oval:ste:1458"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1605" version="1" check="at least one" comment="kernel-smp version is less than 2.4.20-30.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1081"/>
      <state state_ref="oval:org.mitre.oval:ste:1457"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1604" version="1" check="at least one" comment="kernel-bigmem version is less than 2.4.20-30.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1080"/>
      <state state_ref="oval:org.mitre.oval:ste:1456"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1609" version="1" check="at least one" comment="libxml2 version is less than 2.5.10-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1085"/>
      <state state_ref="oval:org.mitre.oval:ste:1461"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1608" version="1" check="at least one" comment="libxml2-devel version is less than 2.5.10-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1084"/>
      <state state_ref="oval:org.mitre.oval:ste:1460"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1607" version="1" check="at least one" comment="libxml2-python version is less than 2.5.10-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1083"/>
      <state state_ref="oval:org.mitre.oval:ste:1459"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1610" version="1" check="at least one" comment="XFree86 version is less than 4.3.0-55.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1086"/>
      <state state_ref="oval:org.mitre.oval:ste:1462"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2965" version="1" check="at least one" comment="File sqlservr.exe version3 less than 2000.80.428.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2779"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1612" version="1" check="at least one" comment="mod_python version is less than 3.0.1-4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1088"/>
      <state state_ref="oval:org.mitre.oval:ste:1464"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1611" version="1" check="at least one" comment="httpd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1087"/>
      <state state_ref="oval:org.mitre.oval:ste:1463"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1613" version="1" check="at least one" comment="samba version is less than 3.0.2-6.3E" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1089"/>
      <state state_ref="oval:org.mitre.oval:ste:1465"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1614" version="1" check="at least one" comment="pwlib version is less than 1.4.7-7.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1090"/>
      <state state_ref="oval:org.mitre.oval:ste:1466"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1617" version="1" check="at least one" comment="kernel version is less than 2.4.21-9.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1093"/>
      <state state_ref="oval:org.mitre.oval:ste:1469"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1616" version="1" check="at least one" comment="kernel-smp version is less than 2.4.21-9.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1092"/>
      <state state_ref="oval:org.mitre.oval:ste:1468"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1615" version="1" check="at least one" comment="kernel-hugemem version is less than 2.4.21-9.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1091"/>
      <state state_ref="oval:org.mitre.oval:ste:1467"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1618" version="1" check="at least one" comment="kdelibs version is less than 3.1-13" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1094"/>
      <state state_ref="oval:org.mitre.oval:ste:1470"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1622" version="1" check="at least one" comment="mc version is less than 4.6.0-7.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1096"/>
      <state state_ref="oval:org.mitre.oval:ste:1474"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1621" version="1" check="at least one" comment="/usr/bin/mc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1095"/>
      <state state_ref="oval:org.mitre.oval:ste:1473"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1620" version="1" check="at least one" comment="/usr/bin/mc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1095"/>
      <state state_ref="oval:org.mitre.oval:ste:1472"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1619" version="1" check="at least one" comment="/usr/bin/mc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1095"/>
      <state state_ref="oval:org.mitre.oval:ste:1471"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1625" version="1" check="at least one" comment="slocate version is less than 2.7-2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1098"/>
      <state state_ref="oval:org.mitre.oval:ste:1477"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1624" version="1" check="at least one" comment="/usr/bin/slocate is setgid" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1097"/>
      <state state_ref="oval:org.mitre.oval:ste:1476"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1623" version="1" check="at least one" comment="/usr/bin/slocate is setgid" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1097"/>
      <state state_ref="oval:org.mitre.oval:ste:1475"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2968" version="1" check="at least one" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1698"/>
      <state state_ref="oval:org.mitre.oval:ste:2782"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2967" version="1" check="at least one" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1697"/>
      <state state_ref="oval:org.mitre.oval:ste:2781"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1629" version="1" check="at least one" comment="gaim version is less than 0.75-0.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1100"/>
      <state state_ref="oval:org.mitre.oval:ste:1481"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1628" version="1" check="at least one" comment="/usr/bin/gaim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1099"/>
      <state state_ref="oval:org.mitre.oval:ste:1480"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1627" version="1" check="at least one" comment="/usr/bin/gaim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1099"/>
      <state state_ref="oval:org.mitre.oval:ste:1479"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1626" version="1" check="at least one" comment="/usr/bin/gaim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1099"/>
      <state state_ref="oval:org.mitre.oval:ste:1478"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1631" version="1" check="at least one" comment="mailman version is less than 2.1.1-5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1102"/>
      <state state_ref="oval:org.mitre.oval:ste:1483"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1634" version="1" check="at least one" comment="mutt version is less than 1.4.1-3.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1103"/>
      <state state_ref="oval:org.mitre.oval:ste:1486"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1637" version="1" check="at least one" comment="netpbm version is less than 9.24-11.30.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1106"/>
      <state state_ref="oval:org.mitre.oval:ste:1489"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1636" version="1" check="at least one" comment="netpbm-devel version is less than 9.24-11.30.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1105"/>
      <state state_ref="oval:org.mitre.oval:ste:1488"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1635" version="1" check="at least one" comment="netpbm-progs version is less than 9.24-11.30.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1104"/>
      <state state_ref="oval:org.mitre.oval:ste:1487"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1641" version="1" check="at least one" comment="XFree86 version is less than 4.3.0-2.90.55" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1108"/>
      <state state_ref="oval:org.mitre.oval:ste:1493"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1640" version="1" check="at least one" comment="/usr/X11R6/bin/XFree86 is SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1107"/>
      <state state_ref="oval:org.mitre.oval:ste:1492"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1639" version="1" check="at least one" comment="/usr/X11R6/bin/XFree86 is SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1107"/>
      <state state_ref="oval:org.mitre.oval:ste:1491"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1638" version="1" check="at least one" comment="/usr/X11R6/bin/XFree86 is SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1107"/>
      <state state_ref="oval:org.mitre.oval:ste:1490"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2319" version="1" check="at least one" comment="netpbm version is less than 9.24-10.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1336"/>
      <state state_ref="oval:org.mitre.oval:ste:2171"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2318" version="1" check="at least one" comment="netpbm-devel version is less than 9.24-10.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1335"/>
      <state state_ref="oval:org.mitre.oval:ste:2170"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2317" version="1" check="at least one" comment="netpbm-progs version is less than 9.24-10.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1334"/>
      <state state_ref="oval:org.mitre.oval:ste:2169"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2316" version="1" check="at least one" comment="/usr/bin/411toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1333"/>
      <state state_ref="oval:org.mitre.oval:ste:2168"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2315" version="1" check="at least one" comment="/usr/bin/411toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1333"/>
      <state state_ref="oval:org.mitre.oval:ste:2167"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2314" version="1" check="at least one" comment="/usr/bin/411toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1333"/>
      <state state_ref="oval:org.mitre.oval:ste:2166"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2313" version="1" check="at least one" comment="/usr/bin/asciitopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1332"/>
      <state state_ref="oval:org.mitre.oval:ste:2165"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2312" version="1" check="at least one" comment="/usr/bin/asciitopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1332"/>
      <state state_ref="oval:org.mitre.oval:ste:2164"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2311" version="1" check="at least one" comment="/usr/bin/asciitopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1332"/>
      <state state_ref="oval:org.mitre.oval:ste:2163"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2310" version="1" check="at least one" comment="/usr/bin/atktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1331"/>
      <state state_ref="oval:org.mitre.oval:ste:2162"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2309" version="1" check="at least one" comment="/usr/bin/atktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1331"/>
      <state state_ref="oval:org.mitre.oval:ste:2161"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2308" version="1" check="at least one" comment="/usr/bin/atktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1331"/>
      <state state_ref="oval:org.mitre.oval:ste:2160"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2307" version="1" check="at least one" comment="/usr/bin/bioradtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1330"/>
      <state state_ref="oval:org.mitre.oval:ste:2159"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2306" version="1" check="at least one" comment="/usr/bin/bioradtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1330"/>
      <state state_ref="oval:org.mitre.oval:ste:2158"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2305" version="1" check="at least one" comment="/usr/bin/bioradtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1330"/>
      <state state_ref="oval:org.mitre.oval:ste:2157"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2304" version="1" check="at least one" comment="/usr/bin/bmptoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1329"/>
      <state state_ref="oval:org.mitre.oval:ste:2156"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2303" version="1" check="at least one" comment="/usr/bin/bmptoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1329"/>
      <state state_ref="oval:org.mitre.oval:ste:2155"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2302" version="1" check="at least one" comment="/usr/bin/bmptoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1329"/>
      <state state_ref="oval:org.mitre.oval:ste:2154"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2301" version="1" check="at least one" comment="/usr/bin/brushtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1328"/>
      <state state_ref="oval:org.mitre.oval:ste:2153"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2300" version="1" check="at least one" comment="/usr/bin/brushtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1328"/>
      <state state_ref="oval:org.mitre.oval:ste:2152"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2299" version="1" check="at least one" comment="/usr/bin/brushtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1328"/>
      <state state_ref="oval:org.mitre.oval:ste:2151"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2298" version="1" check="at least one" comment="/usr/bin/cmuwmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1327"/>
      <state state_ref="oval:org.mitre.oval:ste:2150"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2297" version="1" check="at least one" comment="/usr/bin/cmuwmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1327"/>
      <state state_ref="oval:org.mitre.oval:ste:2149"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2296" version="1" check="at least one" comment="/usr/bin/cmuwmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1327"/>
      <state state_ref="oval:org.mitre.oval:ste:2148"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2295" version="1" check="at least one" comment="/usr/bin/eyuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1326"/>
      <state state_ref="oval:org.mitre.oval:ste:2147"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2294" version="1" check="at least one" comment="/usr/bin/eyuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1326"/>
      <state state_ref="oval:org.mitre.oval:ste:2146"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2293" version="1" check="at least one" comment="/usr/bin/eyuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1326"/>
      <state state_ref="oval:org.mitre.oval:ste:2145"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2292" version="1" check="at least one" comment="/usr/bin/fiascotopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1325"/>
      <state state_ref="oval:org.mitre.oval:ste:2144"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2291" version="1" check="at least one" comment="/usr/bin/fiascotopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1325"/>
      <state state_ref="oval:org.mitre.oval:ste:2143"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2290" version="1" check="at least one" comment="/usr/bin/fiascotopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1325"/>
      <state state_ref="oval:org.mitre.oval:ste:2142"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2289" version="1" check="at least one" comment="/usr/bin/fitstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1324"/>
      <state state_ref="oval:org.mitre.oval:ste:2141"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2288" version="1" check="at least one" comment="/usr/bin/fitstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1324"/>
      <state state_ref="oval:org.mitre.oval:ste:2140"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2287" version="1" check="at least one" comment="/usr/bin/fitstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1324"/>
      <state state_ref="oval:org.mitre.oval:ste:2139"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2286" version="1" check="at least one" comment="/usr/bin/fstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1323"/>
      <state state_ref="oval:org.mitre.oval:ste:2138"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2285" version="1" check="at least one" comment="/usr/bin/fstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1323"/>
      <state state_ref="oval:org.mitre.oval:ste:2137"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2284" version="1" check="at least one" comment="/usr/bin/fstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1323"/>
      <state state_ref="oval:org.mitre.oval:ste:2136"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2283" version="1" check="at least one" comment="/usr/bin/g3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1322"/>
      <state state_ref="oval:org.mitre.oval:ste:2135"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2282" version="1" check="at least one" comment="/usr/bin/g3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1322"/>
      <state state_ref="oval:org.mitre.oval:ste:2134"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2281" version="1" check="at least one" comment="/usr/bin/g3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1322"/>
      <state state_ref="oval:org.mitre.oval:ste:2133"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2280" version="1" check="at least one" comment="/usr/bin/gemtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1321"/>
      <state state_ref="oval:org.mitre.oval:ste:2132"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2279" version="1" check="at least one" comment="/usr/bin/gemtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1321"/>
      <state state_ref="oval:org.mitre.oval:ste:2131"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2278" version="1" check="at least one" comment="/usr/bin/gemtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1321"/>
      <state state_ref="oval:org.mitre.oval:ste:2130"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2277" version="1" check="at least one" comment="/usr/bin/gemtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1320"/>
      <state state_ref="oval:org.mitre.oval:ste:2129"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2276" version="1" check="at least one" comment="/usr/bin/gemtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1320"/>
      <state state_ref="oval:org.mitre.oval:ste:2128"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2275" version="1" check="at least one" comment="/usr/bin/gemtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1320"/>
      <state state_ref="oval:org.mitre.oval:ste:2127"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2274" version="1" check="at least one" comment="/usr/bin/giftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1319"/>
      <state state_ref="oval:org.mitre.oval:ste:2126"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2273" version="1" check="at least one" comment="/usr/bin/giftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1319"/>
      <state state_ref="oval:org.mitre.oval:ste:2125"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2272" version="1" check="at least one" comment="/usr/bin/giftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1319"/>
      <state state_ref="oval:org.mitre.oval:ste:2124"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2271" version="1" check="at least one" comment="/usr/bin/gouldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1318"/>
      <state state_ref="oval:org.mitre.oval:ste:2123"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2270" version="1" check="at least one" comment="/usr/bin/gouldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1318"/>
      <state state_ref="oval:org.mitre.oval:ste:2122"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2269" version="1" check="at least one" comment="/usr/bin/gouldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1318"/>
      <state state_ref="oval:org.mitre.oval:ste:2121"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2268" version="1" check="at least one" comment="/usr/bin/hipstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1317"/>
      <state state_ref="oval:org.mitre.oval:ste:2120"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2267" version="1" check="at least one" comment="/usr/bin/hipstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1317"/>
      <state state_ref="oval:org.mitre.oval:ste:2119"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2266" version="1" check="at least one" comment="/usr/bin/hipstopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1317"/>
      <state state_ref="oval:org.mitre.oval:ste:2118"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2265" version="1" check="at least one" comment="/usr/bin/hpcdtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1316"/>
      <state state_ref="oval:org.mitre.oval:ste:2117"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2264" version="1" check="at least one" comment="/usr/bin/hpcdtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1316"/>
      <state state_ref="oval:org.mitre.oval:ste:2116"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2263" version="1" check="at least one" comment="/usr/bin/hpcdtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1316"/>
      <state state_ref="oval:org.mitre.oval:ste:2115"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2262" version="1" check="at least one" comment="/usr/bin/icontopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1315"/>
      <state state_ref="oval:org.mitre.oval:ste:2114"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2261" version="1" check="at least one" comment="/usr/bin/icontopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1315"/>
      <state state_ref="oval:org.mitre.oval:ste:2113"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2260" version="1" check="at least one" comment="/usr/bin/icontopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1315"/>
      <state state_ref="oval:org.mitre.oval:ste:2112"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2259" version="1" check="at least one" comment="/usr/bin/ilbmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1314"/>
      <state state_ref="oval:org.mitre.oval:ste:2111"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2258" version="1" check="at least one" comment="/usr/bin/ilbmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1314"/>
      <state state_ref="oval:org.mitre.oval:ste:2110"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2257" version="1" check="at least one" comment="/usr/bin/ilbmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1314"/>
      <state state_ref="oval:org.mitre.oval:ste:2109"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2256" version="1" check="at least one" comment="/usr/bin/imgtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1313"/>
      <state state_ref="oval:org.mitre.oval:ste:2108"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2255" version="1" check="at least one" comment="/usr/bin/imgtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1313"/>
      <state state_ref="oval:org.mitre.oval:ste:2107"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2254" version="1" check="at least one" comment="/usr/bin/imgtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1313"/>
      <state state_ref="oval:org.mitre.oval:ste:2106"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2253" version="1" check="at least one" comment="/usr/bin/jpegtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1312"/>
      <state state_ref="oval:org.mitre.oval:ste:2105"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2252" version="1" check="at least one" comment="/usr/bin/jpegtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1312"/>
      <state state_ref="oval:org.mitre.oval:ste:2104"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2251" version="1" check="at least one" comment="/usr/bin/jpegtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1312"/>
      <state state_ref="oval:org.mitre.oval:ste:2103"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2250" version="1" check="at least one" comment="/usr/bin/leaftoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1311"/>
      <state state_ref="oval:org.mitre.oval:ste:2102"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2249" version="1" check="at least one" comment="/usr/bin/leaftoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1311"/>
      <state state_ref="oval:org.mitre.oval:ste:2101"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2248" version="1" check="at least one" comment="/usr/bin/leaftoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1311"/>
      <state state_ref="oval:org.mitre.oval:ste:2100"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2247" version="1" check="at least one" comment="/usr/bin/lispmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1310"/>
      <state state_ref="oval:org.mitre.oval:ste:2099"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2246" version="1" check="at least one" comment="/usr/bin/lispmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1310"/>
      <state state_ref="oval:org.mitre.oval:ste:2098"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2245" version="1" check="at least one" comment="/usr/bin/lispmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1310"/>
      <state state_ref="oval:org.mitre.oval:ste:2097"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2244" version="1" check="at least one" comment="/usr/bin/macptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1309"/>
      <state state_ref="oval:org.mitre.oval:ste:2096"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2243" version="1" check="at least one" comment="/usr/bin/macptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1309"/>
      <state state_ref="oval:org.mitre.oval:ste:2095"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2242" version="1" check="at least one" comment="/usr/bin/macptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1309"/>
      <state state_ref="oval:org.mitre.oval:ste:2094"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2241" version="1" check="at least one" comment="/usr/bin/mdatopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1308"/>
      <state state_ref="oval:org.mitre.oval:ste:2093"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2240" version="1" check="at least one" comment="/usr/bin/mdatopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1308"/>
      <state state_ref="oval:org.mitre.oval:ste:2092"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2239" version="1" check="at least one" comment="/usr/bin/mdatopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1308"/>
      <state state_ref="oval:org.mitre.oval:ste:2091"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2238" version="1" check="at least one" comment="/usr/bin/mgrtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1307"/>
      <state state_ref="oval:org.mitre.oval:ste:2090"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2237" version="1" check="at least one" comment="/usr/bin/mgrtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1307"/>
      <state state_ref="oval:org.mitre.oval:ste:2089"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2236" version="1" check="at least one" comment="/usr/bin/mgrtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1307"/>
      <state state_ref="oval:org.mitre.oval:ste:2088"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2235" version="1" check="at least one" comment="/usr/bin/mtvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1306"/>
      <state state_ref="oval:org.mitre.oval:ste:2087"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2234" version="1" check="at least one" comment="/usr/bin/mtvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1306"/>
      <state state_ref="oval:org.mitre.oval:ste:2086"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2233" version="1" check="at least one" comment="/usr/bin/mtvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1306"/>
      <state state_ref="oval:org.mitre.oval:ste:2085"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2232" version="1" check="at least one" comment="/usr/bin/neotoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1305"/>
      <state state_ref="oval:org.mitre.oval:ste:2084"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2231" version="1" check="at least one" comment="/usr/bin/neotoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1305"/>
      <state state_ref="oval:org.mitre.oval:ste:2083"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2230" version="1" check="at least one" comment="/usr/bin/neotoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1305"/>
      <state state_ref="oval:org.mitre.oval:ste:2082"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2229" version="1" check="at least one" comment="/usr/bin/palmtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1304"/>
      <state state_ref="oval:org.mitre.oval:ste:2081"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2228" version="1" check="at least one" comment="/usr/bin/palmtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1304"/>
      <state state_ref="oval:org.mitre.oval:ste:2080"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2227" version="1" check="at least one" comment="/usr/bin/palmtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1304"/>
      <state state_ref="oval:org.mitre.oval:ste:2079"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2226" version="1" check="at least one" comment="/usr/bin/pamchannel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1303"/>
      <state state_ref="oval:org.mitre.oval:ste:2078"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2225" version="1" check="at least one" comment="/usr/bin/pamchannel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1303"/>
      <state state_ref="oval:org.mitre.oval:ste:2077"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2224" version="1" check="at least one" comment="/usr/bin/pamchannel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1303"/>
      <state state_ref="oval:org.mitre.oval:ste:2076"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2223" version="1" check="at least one" comment="/usr/bin/pamcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1302"/>
      <state state_ref="oval:org.mitre.oval:ste:2075"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2222" version="1" check="at least one" comment="/usr/bin/pamcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1302"/>
      <state state_ref="oval:org.mitre.oval:ste:2074"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2221" version="1" check="at least one" comment="/usr/bin/pamcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1302"/>
      <state state_ref="oval:org.mitre.oval:ste:2073"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2220" version="1" check="at least one" comment="/usr/bin/pamdeinterlace is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1301"/>
      <state state_ref="oval:org.mitre.oval:ste:2072"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2219" version="1" check="at least one" comment="/usr/bin/pamdeinterlace is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1301"/>
      <state state_ref="oval:org.mitre.oval:ste:2071"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2218" version="1" check="at least one" comment="/usr/bin/pamdeinterlace is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1301"/>
      <state state_ref="oval:org.mitre.oval:ste:2070"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2217" version="1" check="at least one" comment="/usr/bin/pamfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1300"/>
      <state state_ref="oval:org.mitre.oval:ste:2069"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2216" version="1" check="at least one" comment="/usr/bin/pamfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1300"/>
      <state state_ref="oval:org.mitre.oval:ste:2068"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2215" version="1" check="at least one" comment="/usr/bin/pamfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1300"/>
      <state state_ref="oval:org.mitre.oval:ste:2067"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2214" version="1" check="at least one" comment="/usr/bin/pamoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1299"/>
      <state state_ref="oval:org.mitre.oval:ste:2066"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2213" version="1" check="at least one" comment="/usr/bin/pamoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1299"/>
      <state state_ref="oval:org.mitre.oval:ste:2065"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2212" version="1" check="at least one" comment="/usr/bin/pamoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1299"/>
      <state state_ref="oval:org.mitre.oval:ste:2064"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2211" version="1" check="at least one" comment="/usr/bin/pamstretch is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1298"/>
      <state state_ref="oval:org.mitre.oval:ste:2063"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2210" version="1" check="at least one" comment="/usr/bin/pamstretch is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1298"/>
      <state state_ref="oval:org.mitre.oval:ste:2062"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2209" version="1" check="at least one" comment="/usr/bin/pamstretch is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1298"/>
      <state state_ref="oval:org.mitre.oval:ste:2061"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2208" version="1" check="at least one" comment="/usr/bin/pamtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1297"/>
      <state state_ref="oval:org.mitre.oval:ste:2060"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2207" version="1" check="at least one" comment="/usr/bin/pamtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1297"/>
      <state state_ref="oval:org.mitre.oval:ste:2059"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2206" version="1" check="at least one" comment="/usr/bin/pamtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1297"/>
      <state state_ref="oval:org.mitre.oval:ste:2058"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2205" version="1" check="at least one" comment="/usr/bin/pbmclean is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1296"/>
      <state state_ref="oval:org.mitre.oval:ste:2057"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2204" version="1" check="at least one" comment="/usr/bin/pbmclean is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1296"/>
      <state state_ref="oval:org.mitre.oval:ste:2056"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2203" version="1" check="at least one" comment="/usr/bin/pbmclean is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1296"/>
      <state state_ref="oval:org.mitre.oval:ste:2055"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2202" version="1" check="at least one" comment="/usr/bin/pbmlife is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1295"/>
      <state state_ref="oval:org.mitre.oval:ste:2054"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2201" version="1" check="at least one" comment="/usr/bin/pbmlife is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1295"/>
      <state state_ref="oval:org.mitre.oval:ste:2053"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2200" version="1" check="at least one" comment="/usr/bin/pbmlife is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1295"/>
      <state state_ref="oval:org.mitre.oval:ste:2052"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2199" version="1" check="at least one" comment="/usr/bin/pbmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1294"/>
      <state state_ref="oval:org.mitre.oval:ste:2051"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2198" version="1" check="at least one" comment="/usr/bin/pbmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1294"/>
      <state state_ref="oval:org.mitre.oval:ste:2050"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2197" version="1" check="at least one" comment="/usr/bin/pbmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1294"/>
      <state state_ref="oval:org.mitre.oval:ste:2049"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2196" version="1" check="at least one" comment="/usr/bin/pbmmask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1293"/>
      <state state_ref="oval:org.mitre.oval:ste:2048"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2195" version="1" check="at least one" comment="/usr/bin/pbmmask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1293"/>
      <state state_ref="oval:org.mitre.oval:ste:2047"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2194" version="1" check="at least one" comment="/usr/bin/pbmmask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1293"/>
      <state state_ref="oval:org.mitre.oval:ste:2046"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2193" version="1" check="at least one" comment="/usr/bin/pbmpage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1292"/>
      <state state_ref="oval:org.mitre.oval:ste:2045"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2192" version="1" check="at least one" comment="/usr/bin/pbmpage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1292"/>
      <state state_ref="oval:org.mitre.oval:ste:2044"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2191" version="1" check="at least one" comment="/usr/bin/pbmpage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1292"/>
      <state state_ref="oval:org.mitre.oval:ste:2043"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2190" version="1" check="at least one" comment="/usr/bin/pbmpscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1291"/>
      <state state_ref="oval:org.mitre.oval:ste:2042"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2189" version="1" check="at least one" comment="/usr/bin/pbmpscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1291"/>
      <state state_ref="oval:org.mitre.oval:ste:2041"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2188" version="1" check="at least one" comment="/usr/bin/pbmpscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1291"/>
      <state state_ref="oval:org.mitre.oval:ste:2040"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2187" version="1" check="at least one" comment="/usr/bin/pbmreduce is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1290"/>
      <state state_ref="oval:org.mitre.oval:ste:2039"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2186" version="1" check="at least one" comment="/usr/bin/pbmreduce is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1290"/>
      <state state_ref="oval:org.mitre.oval:ste:2038"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2185" version="1" check="at least one" comment="/usr/bin/pbmreduce is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1290"/>
      <state state_ref="oval:org.mitre.oval:ste:2037"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2184" version="1" check="at least one" comment="/usr/bin/pbmtext is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1289"/>
      <state state_ref="oval:org.mitre.oval:ste:2036"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2183" version="1" check="at least one" comment="/usr/bin/pbmtext is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1289"/>
      <state state_ref="oval:org.mitre.oval:ste:2035"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2182" version="1" check="at least one" comment="/usr/bin/pbmtext is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1289"/>
      <state state_ref="oval:org.mitre.oval:ste:2034"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2181" version="1" check="at least one" comment="/usr/bin/pbmto10x is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1288"/>
      <state state_ref="oval:org.mitre.oval:ste:2033"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2180" version="1" check="at least one" comment="/usr/bin/pbmto10x is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1288"/>
      <state state_ref="oval:org.mitre.oval:ste:2032"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2179" version="1" check="at least one" comment="/usr/bin/pbmto10x is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1288"/>
      <state state_ref="oval:org.mitre.oval:ste:2031"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2178" version="1" check="at least one" comment="/usr/bin/pbmto4425 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1287"/>
      <state state_ref="oval:org.mitre.oval:ste:2030"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2177" version="1" check="at least one" comment="/usr/bin/pbmto4425 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1287"/>
      <state state_ref="oval:org.mitre.oval:ste:2029"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2176" version="1" check="at least one" comment="/usr/bin/pbmto4425 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1287"/>
      <state state_ref="oval:org.mitre.oval:ste:2028"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2175" version="1" check="at least one" comment="/usr/bin/pbmtoascii is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1286"/>
      <state state_ref="oval:org.mitre.oval:ste:2027"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2174" version="1" check="at least one" comment="/usr/bin/pbmtoascii is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1286"/>
      <state state_ref="oval:org.mitre.oval:ste:2026"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2173" version="1" check="at least one" comment="/usr/bin/pbmtoascii is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1286"/>
      <state state_ref="oval:org.mitre.oval:ste:2025"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2172" version="1" check="at least one" comment="/usr/bin/pbmtoatk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1285"/>
      <state state_ref="oval:org.mitre.oval:ste:2024"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2171" version="1" check="at least one" comment="/usr/bin/pbmtoatk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1285"/>
      <state state_ref="oval:org.mitre.oval:ste:2023"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2170" version="1" check="at least one" comment="/usr/bin/pbmtoatk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1285"/>
      <state state_ref="oval:org.mitre.oval:ste:2022"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2169" version="1" check="at least one" comment="/usr/bin/pbmtobbnbg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1284"/>
      <state state_ref="oval:org.mitre.oval:ste:2021"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2168" version="1" check="at least one" comment="/usr/bin/pbmtobbnbg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1284"/>
      <state state_ref="oval:org.mitre.oval:ste:2020"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2167" version="1" check="at least one" comment="/usr/bin/pbmtobbnbg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1284"/>
      <state state_ref="oval:org.mitre.oval:ste:2019"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2166" version="1" check="at least one" comment="/usr/bin/pbmtocmuwm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1283"/>
      <state state_ref="oval:org.mitre.oval:ste:2018"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2165" version="1" check="at least one" comment="/usr/bin/pbmtocmuwm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1283"/>
      <state state_ref="oval:org.mitre.oval:ste:2017"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2164" version="1" check="at least one" comment="/usr/bin/pbmtocmuwm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1283"/>
      <state state_ref="oval:org.mitre.oval:ste:2016"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2163" version="1" check="at least one" comment="/usr/bin/pbmtoepsi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1282"/>
      <state state_ref="oval:org.mitre.oval:ste:2015"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2162" version="1" check="at least one" comment="/usr/bin/pbmtoepsi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1282"/>
      <state state_ref="oval:org.mitre.oval:ste:2014"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2161" version="1" check="at least one" comment="/usr/bin/pbmtoepsi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1282"/>
      <state state_ref="oval:org.mitre.oval:ste:2013"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2160" version="1" check="at least one" comment="/usr/bin/pbmtoepson is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1281"/>
      <state state_ref="oval:org.mitre.oval:ste:2012"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2159" version="1" check="at least one" comment="/usr/bin/pbmtoepson is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1281"/>
      <state state_ref="oval:org.mitre.oval:ste:2011"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2158" version="1" check="at least one" comment="/usr/bin/pbmtoepson is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1281"/>
      <state state_ref="oval:org.mitre.oval:ste:2010"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2157" version="1" check="at least one" comment="/usr/bin/pbmtog3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1280"/>
      <state state_ref="oval:org.mitre.oval:ste:2009"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2156" version="1" check="at least one" comment="/usr/bin/pbmtog3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1280"/>
      <state state_ref="oval:org.mitre.oval:ste:2008"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2155" version="1" check="at least one" comment="/usr/bin/pbmtog3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1280"/>
      <state state_ref="oval:org.mitre.oval:ste:2007"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2154" version="1" check="at least one" comment="/usr/bin/pbmtogem is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1279"/>
      <state state_ref="oval:org.mitre.oval:ste:2006"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2153" version="1" check="at least one" comment="/usr/bin/pbmtogem is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1279"/>
      <state state_ref="oval:org.mitre.oval:ste:2005"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2152" version="1" check="at least one" comment="/usr/bin/pbmtogem is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1279"/>
      <state state_ref="oval:org.mitre.oval:ste:2004"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2151" version="1" check="at least one" comment="/usr/bin/pbmtogo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1278"/>
      <state state_ref="oval:org.mitre.oval:ste:2003"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2150" version="1" check="at least one" comment="/usr/bin/pbmtogo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1278"/>
      <state state_ref="oval:org.mitre.oval:ste:2002"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2149" version="1" check="at least one" comment="/usr/bin/pbmtogo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1278"/>
      <state state_ref="oval:org.mitre.oval:ste:2001"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2148" version="1" check="at least one" comment="/usr/bin/pbmtoicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1277"/>
      <state state_ref="oval:org.mitre.oval:ste:2000"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2147" version="1" check="at least one" comment="/usr/bin/pbmtoicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1277"/>
      <state state_ref="oval:org.mitre.oval:ste:1999"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2146" version="1" check="at least one" comment="/usr/bin/pbmtoicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1277"/>
      <state state_ref="oval:org.mitre.oval:ste:1998"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2145" version="1" check="at least one" comment="/usr/bin/pbmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1276"/>
      <state state_ref="oval:org.mitre.oval:ste:1997"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2144" version="1" check="at least one" comment="/usr/bin/pbmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1276"/>
      <state state_ref="oval:org.mitre.oval:ste:1996"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2143" version="1" check="at least one" comment="/usr/bin/pbmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1276"/>
      <state state_ref="oval:org.mitre.oval:ste:1995"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2142" version="1" check="at least one" comment="/usr/bin/pbmtoln03 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1275"/>
      <state state_ref="oval:org.mitre.oval:ste:1994"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2141" version="1" check="at least one" comment="/usr/bin/pbmtoln03 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1275"/>
      <state state_ref="oval:org.mitre.oval:ste:1993"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2140" version="1" check="at least one" comment="/usr/bin/pbmtoln03 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1275"/>
      <state state_ref="oval:org.mitre.oval:ste:1992"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2139" version="1" check="at least one" comment="/usr/bin/pbmtolps is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1274"/>
      <state state_ref="oval:org.mitre.oval:ste:1991"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2138" version="1" check="at least one" comment="/usr/bin/pbmtolps is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1274"/>
      <state state_ref="oval:org.mitre.oval:ste:1990"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2137" version="1" check="at least one" comment="/usr/bin/pbmtolps is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1274"/>
      <state state_ref="oval:org.mitre.oval:ste:1989"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2136" version="1" check="at least one" comment="/usr/bin/pbmtomacp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1273"/>
      <state state_ref="oval:org.mitre.oval:ste:1988"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2135" version="1" check="at least one" comment="/usr/bin/pbmtomacp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1273"/>
      <state state_ref="oval:org.mitre.oval:ste:1987"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2134" version="1" check="at least one" comment="/usr/bin/pbmtomacp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1273"/>
      <state state_ref="oval:org.mitre.oval:ste:1986"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2133" version="1" check="at least one" comment="/usr/bin/pbmtomda is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1272"/>
      <state state_ref="oval:org.mitre.oval:ste:1985"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2132" version="1" check="at least one" comment="/usr/bin/pbmtomda is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1272"/>
      <state state_ref="oval:org.mitre.oval:ste:1984"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2131" version="1" check="at least one" comment="/usr/bin/pbmtomda is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1272"/>
      <state state_ref="oval:org.mitre.oval:ste:1983"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2130" version="1" check="at least one" comment="/usr/bin/pbmtomgr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1271"/>
      <state state_ref="oval:org.mitre.oval:ste:1982"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2129" version="1" check="at least one" comment="/usr/bin/pbmtomgr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1271"/>
      <state state_ref="oval:org.mitre.oval:ste:1981"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2128" version="1" check="at least one" comment="/usr/bin/pbmtomgr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1271"/>
      <state state_ref="oval:org.mitre.oval:ste:1980"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2127" version="1" check="at least one" comment="/usr/bin/pbmtonokia is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1270"/>
      <state state_ref="oval:org.mitre.oval:ste:1979"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2126" version="1" check="at least one" comment="/usr/bin/pbmtonokia is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1270"/>
      <state state_ref="oval:org.mitre.oval:ste:1978"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2125" version="1" check="at least one" comment="/usr/bin/pbmtonokia is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1270"/>
      <state state_ref="oval:org.mitre.oval:ste:1977"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2124" version="1" check="at least one" comment="/usr/bin/pbmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1269"/>
      <state state_ref="oval:org.mitre.oval:ste:1976"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2123" version="1" check="at least one" comment="/usr/bin/pbmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1269"/>
      <state state_ref="oval:org.mitre.oval:ste:1975"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2122" version="1" check="at least one" comment="/usr/bin/pbmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1269"/>
      <state state_ref="oval:org.mitre.oval:ste:1974"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2121" version="1" check="at least one" comment="/usr/bin/pbmtopi3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1268"/>
      <state state_ref="oval:org.mitre.oval:ste:1973"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2120" version="1" check="at least one" comment="/usr/bin/pbmtopi3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1268"/>
      <state state_ref="oval:org.mitre.oval:ste:1972"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2119" version="1" check="at least one" comment="/usr/bin/pbmtopi3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1268"/>
      <state state_ref="oval:org.mitre.oval:ste:1971"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2118" version="1" check="at least one" comment="/usr/bin/pbmtopk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1267"/>
      <state state_ref="oval:org.mitre.oval:ste:1970"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2117" version="1" check="at least one" comment="/usr/bin/pbmtopk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1267"/>
      <state state_ref="oval:org.mitre.oval:ste:1969"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2116" version="1" check="at least one" comment="/usr/bin/pbmtopk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1267"/>
      <state state_ref="oval:org.mitre.oval:ste:1968"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2115" version="1" check="at least one" comment="/usr/bin/pbmtoplot is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1266"/>
      <state state_ref="oval:org.mitre.oval:ste:1967"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2114" version="1" check="at least one" comment="/usr/bin/pbmtoplot is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1266"/>
      <state state_ref="oval:org.mitre.oval:ste:1966"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2113" version="1" check="at least one" comment="/usr/bin/pbmtoplot is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1266"/>
      <state state_ref="oval:org.mitre.oval:ste:1965"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2112" version="1" check="at least one" comment="/usr/bin/pbmtoppa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1265"/>
      <state state_ref="oval:org.mitre.oval:ste:1964"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2111" version="1" check="at least one" comment="/usr/bin/pbmtoppa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1265"/>
      <state state_ref="oval:org.mitre.oval:ste:1963"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2110" version="1" check="at least one" comment="/usr/bin/pbmtoppa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1265"/>
      <state state_ref="oval:org.mitre.oval:ste:1962"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2109" version="1" check="at least one" comment="/usr/bin/pbmtopsg3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1264"/>
      <state state_ref="oval:org.mitre.oval:ste:1961"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2108" version="1" check="at least one" comment="/usr/bin/pbmtopsg3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1264"/>
      <state state_ref="oval:org.mitre.oval:ste:1960"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2107" version="1" check="at least one" comment="/usr/bin/pbmtopsg3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1264"/>
      <state state_ref="oval:org.mitre.oval:ste:1959"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2106" version="1" check="at least one" comment="/usr/bin/pbmtoptx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1263"/>
      <state state_ref="oval:org.mitre.oval:ste:1958"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2105" version="1" check="at least one" comment="/usr/bin/pbmtoptx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1263"/>
      <state state_ref="oval:org.mitre.oval:ste:1957"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2104" version="1" check="at least one" comment="/usr/bin/pbmtoptx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1263"/>
      <state state_ref="oval:org.mitre.oval:ste:1956"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2103" version="1" check="at least one" comment="/usr/bin/pbmtowbmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1262"/>
      <state state_ref="oval:org.mitre.oval:ste:1955"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2102" version="1" check="at least one" comment="/usr/bin/pbmtowbmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1262"/>
      <state state_ref="oval:org.mitre.oval:ste:1954"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2101" version="1" check="at least one" comment="/usr/bin/pbmtowbmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1262"/>
      <state state_ref="oval:org.mitre.oval:ste:1953"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2100" version="1" check="at least one" comment="/usr/bin/pbmtox10bm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1261"/>
      <state state_ref="oval:org.mitre.oval:ste:1952"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2099" version="1" check="at least one" comment="/usr/bin/pbmtox10bm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1261"/>
      <state state_ref="oval:org.mitre.oval:ste:1951"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2098" version="1" check="at least one" comment="/usr/bin/pbmtox10bm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1261"/>
      <state state_ref="oval:org.mitre.oval:ste:1950"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2097" version="1" check="at least one" comment="/usr/bin/pbmtoxbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1260"/>
      <state state_ref="oval:org.mitre.oval:ste:1949"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2096" version="1" check="at least one" comment="/usr/bin/pbmtoxbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1260"/>
      <state state_ref="oval:org.mitre.oval:ste:1948"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2095" version="1" check="at least one" comment="/usr/bin/pbmtoxbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1260"/>
      <state state_ref="oval:org.mitre.oval:ste:1947"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2094" version="1" check="at least one" comment="/usr/bin/pbmtoybm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1259"/>
      <state state_ref="oval:org.mitre.oval:ste:1946"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2093" version="1" check="at least one" comment="/usr/bin/pbmtoybm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1259"/>
      <state state_ref="oval:org.mitre.oval:ste:1945"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2092" version="1" check="at least one" comment="/usr/bin/pbmtoybm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1259"/>
      <state state_ref="oval:org.mitre.oval:ste:1944"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2091" version="1" check="at least one" comment="/usr/bin/pbmtozinc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1258"/>
      <state state_ref="oval:org.mitre.oval:ste:1943"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2090" version="1" check="at least one" comment="/usr/bin/pbmtozinc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1258"/>
      <state state_ref="oval:org.mitre.oval:ste:1942"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2089" version="1" check="at least one" comment="/usr/bin/pbmtozinc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1258"/>
      <state state_ref="oval:org.mitre.oval:ste:1941"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2088" version="1" check="at least one" comment="/usr/bin/pbmupc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1257"/>
      <state state_ref="oval:org.mitre.oval:ste:1940"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2087" version="1" check="at least one" comment="/usr/bin/pbmupc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1257"/>
      <state state_ref="oval:org.mitre.oval:ste:1939"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2086" version="1" check="at least one" comment="/usr/bin/pbmupc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1257"/>
      <state state_ref="oval:org.mitre.oval:ste:1938"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2085" version="1" check="at least one" comment="/usr/bin/pcxtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1256"/>
      <state state_ref="oval:org.mitre.oval:ste:1937"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2084" version="1" check="at least one" comment="/usr/bin/pcxtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1256"/>
      <state state_ref="oval:org.mitre.oval:ste:1936"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2083" version="1" check="at least one" comment="/usr/bin/pcxtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1256"/>
      <state state_ref="oval:org.mitre.oval:ste:1935"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2082" version="1" check="at least one" comment="/usr/bin/pgmbentley is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1255"/>
      <state state_ref="oval:org.mitre.oval:ste:1934"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2081" version="1" check="at least one" comment="/usr/bin/pgmbentley is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1255"/>
      <state state_ref="oval:org.mitre.oval:ste:1933"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2080" version="1" check="at least one" comment="/usr/bin/pgmbentley is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1255"/>
      <state state_ref="oval:org.mitre.oval:ste:1932"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2079" version="1" check="at least one" comment="/usr/bin/pgmcrater is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1254"/>
      <state state_ref="oval:org.mitre.oval:ste:1931"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2078" version="1" check="at least one" comment="/usr/bin/pgmcrater is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1254"/>
      <state state_ref="oval:org.mitre.oval:ste:1930"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2077" version="1" check="at least one" comment="/usr/bin/pgmcrater is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1254"/>
      <state state_ref="oval:org.mitre.oval:ste:1929"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2076" version="1" check="at least one" comment="/usr/bin/pgmedge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1253"/>
      <state state_ref="oval:org.mitre.oval:ste:1928"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2075" version="1" check="at least one" comment="/usr/bin/pgmedge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1253"/>
      <state state_ref="oval:org.mitre.oval:ste:1927"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2074" version="1" check="at least one" comment="/usr/bin/pgmedge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1253"/>
      <state state_ref="oval:org.mitre.oval:ste:1926"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2073" version="1" check="at least one" comment="/usr/bin/pgmenhance is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1252"/>
      <state state_ref="oval:org.mitre.oval:ste:1925"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2072" version="1" check="at least one" comment="/usr/bin/pgmenhance is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1252"/>
      <state state_ref="oval:org.mitre.oval:ste:1924"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2071" version="1" check="at least one" comment="/usr/bin/pgmenhance is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1252"/>
      <state state_ref="oval:org.mitre.oval:ste:1923"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2070" version="1" check="at least one" comment="/usr/bin/pgmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1251"/>
      <state state_ref="oval:org.mitre.oval:ste:1922"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2069" version="1" check="at least one" comment="/usr/bin/pgmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1251"/>
      <state state_ref="oval:org.mitre.oval:ste:1921"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2068" version="1" check="at least one" comment="/usr/bin/pgmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1251"/>
      <state state_ref="oval:org.mitre.oval:ste:1920"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2067" version="1" check="at least one" comment="/usr/bin/pgmkernel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1250"/>
      <state state_ref="oval:org.mitre.oval:ste:1919"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2066" version="1" check="at least one" comment="/usr/bin/pgmkernel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1250"/>
      <state state_ref="oval:org.mitre.oval:ste:1918"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2065" version="1" check="at least one" comment="/usr/bin/pgmkernel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1250"/>
      <state state_ref="oval:org.mitre.oval:ste:1917"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2064" version="1" check="at least one" comment="/usr/bin/pgmnoise is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1249"/>
      <state state_ref="oval:org.mitre.oval:ste:1916"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2063" version="1" check="at least one" comment="/usr/bin/pgmnoise is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1249"/>
      <state state_ref="oval:org.mitre.oval:ste:1915"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2062" version="1" check="at least one" comment="/usr/bin/pgmnoise is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1249"/>
      <state state_ref="oval:org.mitre.oval:ste:1914"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2061" version="1" check="at least one" comment="/usr/bin/pgmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1248"/>
      <state state_ref="oval:org.mitre.oval:ste:1913"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2060" version="1" check="at least one" comment="/usr/bin/pgmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1248"/>
      <state state_ref="oval:org.mitre.oval:ste:1912"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2059" version="1" check="at least one" comment="/usr/bin/pgmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1248"/>
      <state state_ref="oval:org.mitre.oval:ste:1911"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2058" version="1" check="at least one" comment="/usr/bin/pgmoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1247"/>
      <state state_ref="oval:org.mitre.oval:ste:1910"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2057" version="1" check="at least one" comment="/usr/bin/pgmoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1247"/>
      <state state_ref="oval:org.mitre.oval:ste:1909"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2056" version="1" check="at least one" comment="/usr/bin/pgmoil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1247"/>
      <state state_ref="oval:org.mitre.oval:ste:1908"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2055" version="1" check="at least one" comment="/usr/bin/pgmramp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1246"/>
      <state state_ref="oval:org.mitre.oval:ste:1907"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2054" version="1" check="at least one" comment="/usr/bin/pgmramp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1246"/>
      <state state_ref="oval:org.mitre.oval:ste:1906"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2053" version="1" check="at least one" comment="/usr/bin/pgmramp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1246"/>
      <state state_ref="oval:org.mitre.oval:ste:1905"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2052" version="1" check="at least one" comment="/usr/bin/pgmslice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1245"/>
      <state state_ref="oval:org.mitre.oval:ste:1904"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2051" version="1" check="at least one" comment="/usr/bin/pgmslice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1245"/>
      <state state_ref="oval:org.mitre.oval:ste:1903"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2050" version="1" check="at least one" comment="/usr/bin/pgmslice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1245"/>
      <state state_ref="oval:org.mitre.oval:ste:1902"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2049" version="1" check="at least one" comment="/usr/bin/pgmtexture is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1244"/>
      <state state_ref="oval:org.mitre.oval:ste:1901"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2048" version="1" check="at least one" comment="/usr/bin/pgmtexture is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1244"/>
      <state state_ref="oval:org.mitre.oval:ste:1900"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2047" version="1" check="at least one" comment="/usr/bin/pgmtexture is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1244"/>
      <state state_ref="oval:org.mitre.oval:ste:1899"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2046" version="1" check="at least one" comment="/usr/bin/pgmtofs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1243"/>
      <state state_ref="oval:org.mitre.oval:ste:1898"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2045" version="1" check="at least one" comment="/usr/bin/pgmtofs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1243"/>
      <state state_ref="oval:org.mitre.oval:ste:1897"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2044" version="1" check="at least one" comment="/usr/bin/pgmtofs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1243"/>
      <state state_ref="oval:org.mitre.oval:ste:1896"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2043" version="1" check="at least one" comment="/usr/bin/pgmtolispm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1242"/>
      <state state_ref="oval:org.mitre.oval:ste:1895"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2042" version="1" check="at least one" comment="/usr/bin/pgmtolispm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1242"/>
      <state state_ref="oval:org.mitre.oval:ste:1894"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2041" version="1" check="at least one" comment="/usr/bin/pgmtolispm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1242"/>
      <state state_ref="oval:org.mitre.oval:ste:1893"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2040" version="1" check="at least one" comment="/usr/bin/pgmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1241"/>
      <state state_ref="oval:org.mitre.oval:ste:1892"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2039" version="1" check="at least one" comment="/usr/bin/pgmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1241"/>
      <state state_ref="oval:org.mitre.oval:ste:1891"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2038" version="1" check="at least one" comment="/usr/bin/pgmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1241"/>
      <state state_ref="oval:org.mitre.oval:ste:1890"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2037" version="1" check="at least one" comment="/usr/bin/pgmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1240"/>
      <state state_ref="oval:org.mitre.oval:ste:1889"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2036" version="1" check="at least one" comment="/usr/bin/pgmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1240"/>
      <state state_ref="oval:org.mitre.oval:ste:1888"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2035" version="1" check="at least one" comment="/usr/bin/pgmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1240"/>
      <state state_ref="oval:org.mitre.oval:ste:1887"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2034" version="1" check="at least one" comment="/usr/bin/pi1toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1239"/>
      <state state_ref="oval:org.mitre.oval:ste:1886"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2033" version="1" check="at least one" comment="/usr/bin/pi1toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1239"/>
      <state state_ref="oval:org.mitre.oval:ste:1885"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2032" version="1" check="at least one" comment="/usr/bin/pi1toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1239"/>
      <state state_ref="oval:org.mitre.oval:ste:1884"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2031" version="1" check="at least one" comment="/usr/bin/pi3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1238"/>
      <state state_ref="oval:org.mitre.oval:ste:1883"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2030" version="1" check="at least one" comment="/usr/bin/pi3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1238"/>
      <state state_ref="oval:org.mitre.oval:ste:1882"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2029" version="1" check="at least one" comment="/usr/bin/pi3topbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1238"/>
      <state state_ref="oval:org.mitre.oval:ste:1881"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2028" version="1" check="at least one" comment="/usr/bin/pjtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1237"/>
      <state state_ref="oval:org.mitre.oval:ste:1880"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2027" version="1" check="at least one" comment="/usr/bin/pjtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1237"/>
      <state state_ref="oval:org.mitre.oval:ste:1879"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2026" version="1" check="at least one" comment="/usr/bin/pjtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1237"/>
      <state state_ref="oval:org.mitre.oval:ste:1878"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2025" version="1" check="at least one" comment="/usr/bin/pktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1236"/>
      <state state_ref="oval:org.mitre.oval:ste:1877"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2024" version="1" check="at least one" comment="/usr/bin/pktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1236"/>
      <state state_ref="oval:org.mitre.oval:ste:1876"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2023" version="1" check="at least one" comment="/usr/bin/pktopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1236"/>
      <state state_ref="oval:org.mitre.oval:ste:1875"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2022" version="1" check="at least one" comment="/usr/bin/pngtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1235"/>
      <state state_ref="oval:org.mitre.oval:ste:1874"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2021" version="1" check="at least one" comment="/usr/bin/pngtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1235"/>
      <state state_ref="oval:org.mitre.oval:ste:1873"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2020" version="1" check="at least one" comment="/usr/bin/pngtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1235"/>
      <state state_ref="oval:org.mitre.oval:ste:1872"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2019" version="1" check="at least one" comment="/usr/bin/pnmalias is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1234"/>
      <state state_ref="oval:org.mitre.oval:ste:1871"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2018" version="1" check="at least one" comment="/usr/bin/pnmalias is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1234"/>
      <state state_ref="oval:org.mitre.oval:ste:1870"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2017" version="1" check="at least one" comment="/usr/bin/pnmalias is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1234"/>
      <state state_ref="oval:org.mitre.oval:ste:1869"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2016" version="1" check="at least one" comment="/usr/bin/pnmarith is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1233"/>
      <state state_ref="oval:org.mitre.oval:ste:1868"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2015" version="1" check="at least one" comment="/usr/bin/pnmarith is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1233"/>
      <state state_ref="oval:org.mitre.oval:ste:1867"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2014" version="1" check="at least one" comment="/usr/bin/pnmarith is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1233"/>
      <state state_ref="oval:org.mitre.oval:ste:1866"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2013" version="1" check="at least one" comment="/usr/bin/pnmcat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1232"/>
      <state state_ref="oval:org.mitre.oval:ste:1865"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2012" version="1" check="at least one" comment="/usr/bin/pnmcat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1232"/>
      <state state_ref="oval:org.mitre.oval:ste:1864"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2011" version="1" check="at least one" comment="/usr/bin/pnmcat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1232"/>
      <state state_ref="oval:org.mitre.oval:ste:1863"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2010" version="1" check="at least one" comment="/usr/bin/pnmcolormap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1231"/>
      <state state_ref="oval:org.mitre.oval:ste:1862"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2009" version="1" check="at least one" comment="/usr/bin/pnmcolormap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1231"/>
      <state state_ref="oval:org.mitre.oval:ste:1861"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2008" version="1" check="at least one" comment="/usr/bin/pnmcolormap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1231"/>
      <state state_ref="oval:org.mitre.oval:ste:1860"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2007" version="1" check="at least one" comment="/usr/bin/pnmcomp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1230"/>
      <state state_ref="oval:org.mitre.oval:ste:1859"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2006" version="1" check="at least one" comment="/usr/bin/pnmcomp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1230"/>
      <state state_ref="oval:org.mitre.oval:ste:1858"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2005" version="1" check="at least one" comment="/usr/bin/pnmcomp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1230"/>
      <state state_ref="oval:org.mitre.oval:ste:1857"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2004" version="1" check="at least one" comment="/usr/bin/pnmconvol is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1229"/>
      <state state_ref="oval:org.mitre.oval:ste:1856"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2003" version="1" check="at least one" comment="/usr/bin/pnmconvol is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1229"/>
      <state state_ref="oval:org.mitre.oval:ste:1855"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2002" version="1" check="at least one" comment="/usr/bin/pnmconvol is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1229"/>
      <state state_ref="oval:org.mitre.oval:ste:1854"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2001" version="1" check="at least one" comment="/usr/bin/pnmcrop is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1228"/>
      <state state_ref="oval:org.mitre.oval:ste:1853"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2000" version="1" check="at least one" comment="/usr/bin/pnmcrop is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1228"/>
      <state state_ref="oval:org.mitre.oval:ste:1852"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1999" version="1" check="at least one" comment="/usr/bin/pnmcrop is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1228"/>
      <state state_ref="oval:org.mitre.oval:ste:1851"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1998" version="1" check="at least one" comment="/usr/bin/pnmcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1227"/>
      <state state_ref="oval:org.mitre.oval:ste:1850"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1997" version="1" check="at least one" comment="/usr/bin/pnmcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1227"/>
      <state state_ref="oval:org.mitre.oval:ste:1849"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1996" version="1" check="at least one" comment="/usr/bin/pnmcut is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1227"/>
      <state state_ref="oval:org.mitre.oval:ste:1848"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1995" version="1" check="at least one" comment="/usr/bin/pnmdepth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1226"/>
      <state state_ref="oval:org.mitre.oval:ste:1847"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1994" version="1" check="at least one" comment="/usr/bin/pnmdepth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1226"/>
      <state state_ref="oval:org.mitre.oval:ste:1846"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1993" version="1" check="at least one" comment="/usr/bin/pnmdepth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1226"/>
      <state state_ref="oval:org.mitre.oval:ste:1845"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1992" version="1" check="at least one" comment="/usr/bin/pnmenlarge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1225"/>
      <state state_ref="oval:org.mitre.oval:ste:1844"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1991" version="1" check="at least one" comment="/usr/bin/pnmenlarge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1225"/>
      <state state_ref="oval:org.mitre.oval:ste:1843"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1990" version="1" check="at least one" comment="/usr/bin/pnmenlarge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1225"/>
      <state state_ref="oval:org.mitre.oval:ste:1842"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1989" version="1" check="at least one" comment="/usr/bin/pnmfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1224"/>
      <state state_ref="oval:org.mitre.oval:ste:1841"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1988" version="1" check="at least one" comment="/usr/bin/pnmfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1224"/>
      <state state_ref="oval:org.mitre.oval:ste:1840"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1987" version="1" check="at least one" comment="/usr/bin/pnmfile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1224"/>
      <state state_ref="oval:org.mitre.oval:ste:1839"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1986" version="1" check="at least one" comment="/usr/bin/pnmflip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1223"/>
      <state state_ref="oval:org.mitre.oval:ste:1838"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1985" version="1" check="at least one" comment="/usr/bin/pnmflip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1223"/>
      <state state_ref="oval:org.mitre.oval:ste:1837"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1984" version="1" check="at least one" comment="/usr/bin/pnmflip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1223"/>
      <state state_ref="oval:org.mitre.oval:ste:1836"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1983" version="1" check="at least one" comment="/usr/bin/pnmgamma is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1222"/>
      <state state_ref="oval:org.mitre.oval:ste:1835"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1982" version="1" check="at least one" comment="/usr/bin/pnmgamma is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1222"/>
      <state state_ref="oval:org.mitre.oval:ste:1834"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1981" version="1" check="at least one" comment="/usr/bin/pnmgamma is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1222"/>
      <state state_ref="oval:org.mitre.oval:ste:1833"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1980" version="1" check="at least one" comment="/usr/bin/pnmhisteq is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1221"/>
      <state state_ref="oval:org.mitre.oval:ste:1832"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1979" version="1" check="at least one" comment="/usr/bin/pnmhisteq is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1221"/>
      <state state_ref="oval:org.mitre.oval:ste:1831"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1978" version="1" check="at least one" comment="/usr/bin/pnmhisteq is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1221"/>
      <state state_ref="oval:org.mitre.oval:ste:1830"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1977" version="1" check="at least one" comment="/usr/bin/pnmhistmap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1220"/>
      <state state_ref="oval:org.mitre.oval:ste:1829"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1976" version="1" check="at least one" comment="/usr/bin/pnmhistmap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1220"/>
      <state state_ref="oval:org.mitre.oval:ste:1828"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1975" version="1" check="at least one" comment="/usr/bin/pnmhistmap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1220"/>
      <state state_ref="oval:org.mitre.oval:ste:1827"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1974" version="1" check="at least one" comment="/usr/bin/pnminterp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1219"/>
      <state state_ref="oval:org.mitre.oval:ste:1826"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1973" version="1" check="at least one" comment="/usr/bin/pnminterp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1219"/>
      <state state_ref="oval:org.mitre.oval:ste:1825"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1972" version="1" check="at least one" comment="/usr/bin/pnminterp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1219"/>
      <state state_ref="oval:org.mitre.oval:ste:1824"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1971" version="1" check="at least one" comment="/usr/bin/pnminvert is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1218"/>
      <state state_ref="oval:org.mitre.oval:ste:1823"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1970" version="1" check="at least one" comment="/usr/bin/pnminvert is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1218"/>
      <state state_ref="oval:org.mitre.oval:ste:1822"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1969" version="1" check="at least one" comment="/usr/bin/pnminvert is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1218"/>
      <state state_ref="oval:org.mitre.oval:ste:1821"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1968" version="1" check="at least one" comment="/usr/bin/pnmmontage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1217"/>
      <state state_ref="oval:org.mitre.oval:ste:1820"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1967" version="1" check="at least one" comment="/usr/bin/pnmmontage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1217"/>
      <state state_ref="oval:org.mitre.oval:ste:1819"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1966" version="1" check="at least one" comment="/usr/bin/pnmmontage is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1217"/>
      <state state_ref="oval:org.mitre.oval:ste:1818"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1965" version="1" check="at least one" comment="/usr/bin/pnmnlfilt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1216"/>
      <state state_ref="oval:org.mitre.oval:ste:1817"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1964" version="1" check="at least one" comment="/usr/bin/pnmnlfilt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1216"/>
      <state state_ref="oval:org.mitre.oval:ste:1816"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1963" version="1" check="at least one" comment="/usr/bin/pnmnlfilt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1216"/>
      <state state_ref="oval:org.mitre.oval:ste:1815"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1962" version="1" check="at least one" comment="/usr/bin/pnmnoraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1215"/>
      <state state_ref="oval:org.mitre.oval:ste:1814"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1961" version="1" check="at least one" comment="/usr/bin/pnmnoraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1215"/>
      <state state_ref="oval:org.mitre.oval:ste:1813"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1960" version="1" check="at least one" comment="/usr/bin/pnmnoraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1215"/>
      <state state_ref="oval:org.mitre.oval:ste:1812"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1959" version="1" check="at least one" comment="/usr/bin/pnmpad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1214"/>
      <state state_ref="oval:org.mitre.oval:ste:1811"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1958" version="1" check="at least one" comment="/usr/bin/pnmpad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1214"/>
      <state state_ref="oval:org.mitre.oval:ste:1810"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1957" version="1" check="at least one" comment="/usr/bin/pnmpad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1214"/>
      <state state_ref="oval:org.mitre.oval:ste:1809"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1956" version="1" check="at least one" comment="/usr/bin/pnmpaste is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1213"/>
      <state state_ref="oval:org.mitre.oval:ste:1808"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1955" version="1" check="at least one" comment="/usr/bin/pnmpaste is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1213"/>
      <state state_ref="oval:org.mitre.oval:ste:1807"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1954" version="1" check="at least one" comment="/usr/bin/pnmpaste is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1213"/>
      <state state_ref="oval:org.mitre.oval:ste:1806"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1953" version="1" check="at least one" comment="/usr/bin/pnmpsnr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1212"/>
      <state state_ref="oval:org.mitre.oval:ste:1805"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1952" version="1" check="at least one" comment="/usr/bin/pnmpsnr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1212"/>
      <state state_ref="oval:org.mitre.oval:ste:1804"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1951" version="1" check="at least one" comment="/usr/bin/pnmpsnr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1212"/>
      <state state_ref="oval:org.mitre.oval:ste:1803"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1950" version="1" check="at least one" comment="/usr/bin/pnmremap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1211"/>
      <state state_ref="oval:org.mitre.oval:ste:1802"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1949" version="1" check="at least one" comment="/usr/bin/pnmremap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1211"/>
      <state state_ref="oval:org.mitre.oval:ste:1801"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1948" version="1" check="at least one" comment="/usr/bin/pnmremap is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1211"/>
      <state state_ref="oval:org.mitre.oval:ste:1800"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1947" version="1" check="at least one" comment="/usr/bin/pnmrotate is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1210"/>
      <state state_ref="oval:org.mitre.oval:ste:1799"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1946" version="1" check="at least one" comment="/usr/bin/pnmrotate is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1210"/>
      <state state_ref="oval:org.mitre.oval:ste:1798"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1945" version="1" check="at least one" comment="/usr/bin/pnmrotate is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1210"/>
      <state state_ref="oval:org.mitre.oval:ste:1797"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1944" version="1" check="at least one" comment="/usr/bin/pnmscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1209"/>
      <state state_ref="oval:org.mitre.oval:ste:1796"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1943" version="1" check="at least one" comment="/usr/bin/pnmscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1209"/>
      <state state_ref="oval:org.mitre.oval:ste:1795"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1942" version="1" check="at least one" comment="/usr/bin/pnmscale is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1209"/>
      <state state_ref="oval:org.mitre.oval:ste:1794"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1941" version="1" check="at least one" comment="/usr/bin/ppmtopict is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1208"/>
      <state state_ref="oval:org.mitre.oval:ste:1793"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1940" version="1" check="at least one" comment="/usr/bin/ppmtopict is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1208"/>
      <state state_ref="oval:org.mitre.oval:ste:1792"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1939" version="1" check="at least one" comment="/usr/bin/ppmtopict is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1208"/>
      <state state_ref="oval:org.mitre.oval:ste:1791"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1938" version="1" check="at least one" comment="/usr/bin/ppmtopj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1207"/>
      <state state_ref="oval:org.mitre.oval:ste:1790"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1937" version="1" check="at least one" comment="/usr/bin/ppmtopj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1207"/>
      <state state_ref="oval:org.mitre.oval:ste:1789"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1936" version="1" check="at least one" comment="/usr/bin/ppmtopj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1207"/>
      <state state_ref="oval:org.mitre.oval:ste:1788"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1935" version="1" check="at least one" comment="/usr/bin/ppmtopjxl is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1206"/>
      <state state_ref="oval:org.mitre.oval:ste:1787"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1934" version="1" check="at least one" comment="/usr/bin/ppmtopjxl is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1206"/>
      <state state_ref="oval:org.mitre.oval:ste:1786"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1933" version="1" check="at least one" comment="/usr/bin/ppmtopjxl is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1206"/>
      <state state_ref="oval:org.mitre.oval:ste:1785"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1932" version="1" check="at least one" comment="/usr/bin/ppmtopuzz is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1205"/>
      <state state_ref="oval:org.mitre.oval:ste:1784"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1931" version="1" check="at least one" comment="/usr/bin/ppmtopuzz is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1205"/>
      <state state_ref="oval:org.mitre.oval:ste:1783"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1930" version="1" check="at least one" comment="/usr/bin/ppmtopuzz is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1205"/>
      <state state_ref="oval:org.mitre.oval:ste:1782"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1929" version="1" check="at least one" comment="/usr/bin/ppmtorgb3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1204"/>
      <state state_ref="oval:org.mitre.oval:ste:1781"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1928" version="1" check="at least one" comment="/usr/bin/ppmtorgb3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1204"/>
      <state state_ref="oval:org.mitre.oval:ste:1780"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1927" version="1" check="at least one" comment="/usr/bin/ppmtorgb3 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1204"/>
      <state state_ref="oval:org.mitre.oval:ste:1779"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1926" version="1" check="at least one" comment="/usr/bin/ppmtosixel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1203"/>
      <state state_ref="oval:org.mitre.oval:ste:1778"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1925" version="1" check="at least one" comment="/usr/bin/ppmtosixel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1203"/>
      <state state_ref="oval:org.mitre.oval:ste:1777"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1924" version="1" check="at least one" comment="/usr/bin/ppmtosixel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1203"/>
      <state state_ref="oval:org.mitre.oval:ste:1776"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1923" version="1" check="at least one" comment="/usr/bin/ppmtotga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1202"/>
      <state state_ref="oval:org.mitre.oval:ste:1775"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1922" version="1" check="at least one" comment="/usr/bin/ppmtotga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1202"/>
      <state state_ref="oval:org.mitre.oval:ste:1774"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1921" version="1" check="at least one" comment="/usr/bin/ppmtotga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1202"/>
      <state state_ref="oval:org.mitre.oval:ste:1773"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1920" version="1" check="at least one" comment="/usr/bin/ppmtouil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1201"/>
      <state state_ref="oval:org.mitre.oval:ste:1772"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1919" version="1" check="at least one" comment="/usr/bin/ppmtouil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1201"/>
      <state state_ref="oval:org.mitre.oval:ste:1771"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1918" version="1" check="at least one" comment="/usr/bin/ppmtouil is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1201"/>
      <state state_ref="oval:org.mitre.oval:ste:1770"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1917" version="1" check="at least one" comment="/usr/bin/ppmtowinicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1200"/>
      <state state_ref="oval:org.mitre.oval:ste:1769"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1916" version="1" check="at least one" comment="/usr/bin/ppmtowinicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1200"/>
      <state state_ref="oval:org.mitre.oval:ste:1768"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1915" version="1" check="at least one" comment="/usr/bin/ppmtowinicon is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1200"/>
      <state state_ref="oval:org.mitre.oval:ste:1767"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1914" version="1" check="at least one" comment="/usr/bin/ppmtoxpm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1199"/>
      <state state_ref="oval:org.mitre.oval:ste:1766"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1913" version="1" check="at least one" comment="/usr/bin/ppmtoxpm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1199"/>
      <state state_ref="oval:org.mitre.oval:ste:1765"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1912" version="1" check="at least one" comment="/usr/bin/ppmtoxpm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1199"/>
      <state state_ref="oval:org.mitre.oval:ste:1764"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1911" version="1" check="at least one" comment="/usr/bin/ppmtoyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1198"/>
      <state state_ref="oval:org.mitre.oval:ste:1763"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1910" version="1" check="at least one" comment="/usr/bin/ppmtoyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1198"/>
      <state state_ref="oval:org.mitre.oval:ste:1762"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1909" version="1" check="at least one" comment="/usr/bin/ppmtoyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1198"/>
      <state state_ref="oval:org.mitre.oval:ste:1761"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1908" version="1" check="at least one" comment="/usr/bin/ppmtoyuvsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1197"/>
      <state state_ref="oval:org.mitre.oval:ste:1760"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1907" version="1" check="at least one" comment="/usr/bin/ppmtoyuvsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1197"/>
      <state state_ref="oval:org.mitre.oval:ste:1759"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1906" version="1" check="at least one" comment="/usr/bin/ppmtoyuvsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1197"/>
      <state state_ref="oval:org.mitre.oval:ste:1758"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1905" version="1" check="at least one" comment="/usr/bin/ppmtv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1196"/>
      <state state_ref="oval:org.mitre.oval:ste:1757"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1904" version="1" check="at least one" comment="/usr/bin/ppmtv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1196"/>
      <state state_ref="oval:org.mitre.oval:ste:1756"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1903" version="1" check="at least one" comment="/usr/bin/ppmtv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1196"/>
      <state state_ref="oval:org.mitre.oval:ste:1755"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1902" version="1" check="at least one" comment="/usr/bin/psidtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1195"/>
      <state state_ref="oval:org.mitre.oval:ste:1754"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1901" version="1" check="at least one" comment="/usr/bin/psidtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1195"/>
      <state state_ref="oval:org.mitre.oval:ste:1753"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1900" version="1" check="at least one" comment="/usr/bin/psidtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1195"/>
      <state state_ref="oval:org.mitre.oval:ste:1752"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1899" version="1" check="at least one" comment="/usr/bin/pstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1194"/>
      <state state_ref="oval:org.mitre.oval:ste:1751"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1898" version="1" check="at least one" comment="/usr/bin/pstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1194"/>
      <state state_ref="oval:org.mitre.oval:ste:1750"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1897" version="1" check="at least one" comment="/usr/bin/pstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1194"/>
      <state state_ref="oval:org.mitre.oval:ste:1749"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1896" version="1" check="at least one" comment="/usr/bin/qrttoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1193"/>
      <state state_ref="oval:org.mitre.oval:ste:1748"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1895" version="1" check="at least one" comment="/usr/bin/qrttoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1193"/>
      <state state_ref="oval:org.mitre.oval:ste:1747"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1894" version="1" check="at least one" comment="/usr/bin/qrttoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1193"/>
      <state state_ref="oval:org.mitre.oval:ste:1746"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1893" version="1" check="at least one" comment="/usr/bin/rasttopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1192"/>
      <state state_ref="oval:org.mitre.oval:ste:1745"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1892" version="1" check="at least one" comment="/usr/bin/rasttopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1192"/>
      <state state_ref="oval:org.mitre.oval:ste:1744"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1891" version="1" check="at least one" comment="/usr/bin/rasttopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1192"/>
      <state state_ref="oval:org.mitre.oval:ste:1743"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1890" version="1" check="at least one" comment="/usr/bin/rawtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1191"/>
      <state state_ref="oval:org.mitre.oval:ste:1742"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1889" version="1" check="at least one" comment="/usr/bin/rawtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1191"/>
      <state state_ref="oval:org.mitre.oval:ste:1741"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1888" version="1" check="at least one" comment="/usr/bin/rawtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1191"/>
      <state state_ref="oval:org.mitre.oval:ste:1740"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1887" version="1" check="at least one" comment="/usr/bin/rawtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1190"/>
      <state state_ref="oval:org.mitre.oval:ste:1739"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1886" version="1" check="at least one" comment="/usr/bin/rawtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1190"/>
      <state state_ref="oval:org.mitre.oval:ste:1738"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1885" version="1" check="at least one" comment="/usr/bin/rawtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1190"/>
      <state state_ref="oval:org.mitre.oval:ste:1737"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1884" version="1" check="at least one" comment="/usr/bin/rgb3toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1189"/>
      <state state_ref="oval:org.mitre.oval:ste:1736"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1883" version="1" check="at least one" comment="/usr/bin/rgb3toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1189"/>
      <state state_ref="oval:org.mitre.oval:ste:1735"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1882" version="1" check="at least one" comment="/usr/bin/rgb3toppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1189"/>
      <state state_ref="oval:org.mitre.oval:ste:1734"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1881" version="1" check="at least one" comment="/usr/bin/rletopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1188"/>
      <state state_ref="oval:org.mitre.oval:ste:1733"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1880" version="1" check="at least one" comment="/usr/bin/rletopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1188"/>
      <state state_ref="oval:org.mitre.oval:ste:1732"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1879" version="1" check="at least one" comment="/usr/bin/rletopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1188"/>
      <state state_ref="oval:org.mitre.oval:ste:1731"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1878" version="1" check="at least one" comment="/usr/bin/sbigtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1187"/>
      <state state_ref="oval:org.mitre.oval:ste:1730"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1877" version="1" check="at least one" comment="/usr/bin/sbigtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1187"/>
      <state state_ref="oval:org.mitre.oval:ste:1729"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1876" version="1" check="at least one" comment="/usr/bin/sbigtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1187"/>
      <state state_ref="oval:org.mitre.oval:ste:1728"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1875" version="1" check="at least one" comment="/usr/bin/sgitopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1186"/>
      <state state_ref="oval:org.mitre.oval:ste:1727"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1874" version="1" check="at least one" comment="/usr/bin/sgitopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1186"/>
      <state state_ref="oval:org.mitre.oval:ste:1726"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1873" version="1" check="at least one" comment="/usr/bin/sgitopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1186"/>
      <state state_ref="oval:org.mitre.oval:ste:1725"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1872" version="1" check="at least one" comment="/usr/bin/sirtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1185"/>
      <state state_ref="oval:org.mitre.oval:ste:1724"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1871" version="1" check="at least one" comment="/usr/bin/sirtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1185"/>
      <state state_ref="oval:org.mitre.oval:ste:1723"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1870" version="1" check="at least one" comment="/usr/bin/sirtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1185"/>
      <state state_ref="oval:org.mitre.oval:ste:1722"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1869" version="1" check="at least one" comment="/usr/bin/sldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1184"/>
      <state state_ref="oval:org.mitre.oval:ste:1721"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1868" version="1" check="at least one" comment="/usr/bin/sldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1184"/>
      <state state_ref="oval:org.mitre.oval:ste:1720"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1867" version="1" check="at least one" comment="/usr/bin/sldtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1184"/>
      <state state_ref="oval:org.mitre.oval:ste:1719"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1866" version="1" check="at least one" comment="/usr/bin/spctoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1183"/>
      <state state_ref="oval:org.mitre.oval:ste:1718"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1865" version="1" check="at least one" comment="/usr/bin/spctoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1183"/>
      <state state_ref="oval:org.mitre.oval:ste:1717"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1864" version="1" check="at least one" comment="/usr/bin/spctoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1183"/>
      <state state_ref="oval:org.mitre.oval:ste:1716"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1863" version="1" check="at least one" comment="/usr/bin/spottopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1182"/>
      <state state_ref="oval:org.mitre.oval:ste:1715"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1862" version="1" check="at least one" comment="/usr/bin/spottopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1182"/>
      <state state_ref="oval:org.mitre.oval:ste:1714"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1861" version="1" check="at least one" comment="/usr/bin/spottopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1182"/>
      <state state_ref="oval:org.mitre.oval:ste:1713"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1860" version="1" check="at least one" comment="/usr/bin/sputoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1181"/>
      <state state_ref="oval:org.mitre.oval:ste:1712"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1859" version="1" check="at least one" comment="/usr/bin/sputoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1181"/>
      <state state_ref="oval:org.mitre.oval:ste:1711"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1858" version="1" check="at least one" comment="/usr/bin/sputoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1181"/>
      <state state_ref="oval:org.mitre.oval:ste:1710"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1857" version="1" check="at least one" comment="/usr/bin/tgatoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1180"/>
      <state state_ref="oval:org.mitre.oval:ste:1709"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1856" version="1" check="at least one" comment="/usr/bin/tgatoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1180"/>
      <state state_ref="oval:org.mitre.oval:ste:1708"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1855" version="1" check="at least one" comment="/usr/bin/tgatoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1180"/>
      <state state_ref="oval:org.mitre.oval:ste:1707"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1854" version="1" check="at least one" comment="/usr/bin/thinkjettopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1179"/>
      <state state_ref="oval:org.mitre.oval:ste:1706"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1853" version="1" check="at least one" comment="/usr/bin/thinkjettopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1179"/>
      <state state_ref="oval:org.mitre.oval:ste:1705"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1852" version="1" check="at least one" comment="/usr/bin/thinkjettopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1179"/>
      <state state_ref="oval:org.mitre.oval:ste:1704"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1851" version="1" check="at least one" comment="/usr/bin/tifftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1178"/>
      <state state_ref="oval:org.mitre.oval:ste:1703"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1850" version="1" check="at least one" comment="/usr/bin/tifftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1178"/>
      <state state_ref="oval:org.mitre.oval:ste:1702"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1849" version="1" check="at least one" comment="/usr/bin/tifftopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1178"/>
      <state state_ref="oval:org.mitre.oval:ste:1701"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1848" version="1" check="at least one" comment="/usr/bin/wbmptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1177"/>
      <state state_ref="oval:org.mitre.oval:ste:1700"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1847" version="1" check="at least one" comment="/usr/bin/wbmptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1177"/>
      <state state_ref="oval:org.mitre.oval:ste:1699"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1846" version="1" check="at least one" comment="/usr/bin/wbmptopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1177"/>
      <state state_ref="oval:org.mitre.oval:ste:1698"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1845" version="1" check="at least one" comment="/usr/bin/winicontoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1176"/>
      <state state_ref="oval:org.mitre.oval:ste:1697"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1844" version="1" check="at least one" comment="/usr/bin/winicontoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1176"/>
      <state state_ref="oval:org.mitre.oval:ste:1696"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1843" version="1" check="at least one" comment="/usr/bin/winicontoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1176"/>
      <state state_ref="oval:org.mitre.oval:ste:1695"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1842" version="1" check="at least one" comment="/usr/bin/xbmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1175"/>
      <state state_ref="oval:org.mitre.oval:ste:1694"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1841" version="1" check="at least one" comment="/usr/bin/xbmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1175"/>
      <state state_ref="oval:org.mitre.oval:ste:1693"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1840" version="1" check="at least one" comment="/usr/bin/xbmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1175"/>
      <state state_ref="oval:org.mitre.oval:ste:1692"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1839" version="1" check="at least one" comment="/usr/bin/ximtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1174"/>
      <state state_ref="oval:org.mitre.oval:ste:1691"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1838" version="1" check="at least one" comment="/usr/bin/ximtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1174"/>
      <state state_ref="oval:org.mitre.oval:ste:1690"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1837" version="1" check="at least one" comment="/usr/bin/ximtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1174"/>
      <state state_ref="oval:org.mitre.oval:ste:1689"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1836" version="1" check="at least one" comment="/usr/bin/xpmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1173"/>
      <state state_ref="oval:org.mitre.oval:ste:1688"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1835" version="1" check="at least one" comment="/usr/bin/xpmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1173"/>
      <state state_ref="oval:org.mitre.oval:ste:1687"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1834" version="1" check="at least one" comment="/usr/bin/xpmtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1173"/>
      <state state_ref="oval:org.mitre.oval:ste:1686"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1833" version="1" check="at least one" comment="/usr/bin/xvminitoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1172"/>
      <state state_ref="oval:org.mitre.oval:ste:1685"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1832" version="1" check="at least one" comment="/usr/bin/xvminitoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1172"/>
      <state state_ref="oval:org.mitre.oval:ste:1684"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1831" version="1" check="at least one" comment="/usr/bin/xvminitoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1172"/>
      <state state_ref="oval:org.mitre.oval:ste:1683"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1830" version="1" check="at least one" comment="/usr/bin/xwdtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1171"/>
      <state state_ref="oval:org.mitre.oval:ste:1682"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1829" version="1" check="at least one" comment="/usr/bin/xwdtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1171"/>
      <state state_ref="oval:org.mitre.oval:ste:1681"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1828" version="1" check="at least one" comment="/usr/bin/xwdtopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1171"/>
      <state state_ref="oval:org.mitre.oval:ste:1680"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1827" version="1" check="at least one" comment="/usr/bin/ybmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1170"/>
      <state state_ref="oval:org.mitre.oval:ste:1679"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1826" version="1" check="at least one" comment="/usr/bin/ybmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1170"/>
      <state state_ref="oval:org.mitre.oval:ste:1678"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1825" version="1" check="at least one" comment="/usr/bin/ybmtopbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1170"/>
      <state state_ref="oval:org.mitre.oval:ste:1677"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1824" version="1" check="at least one" comment="/usr/bin/yuvsplittoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1169"/>
      <state state_ref="oval:org.mitre.oval:ste:1676"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1823" version="1" check="at least one" comment="/usr/bin/yuvsplittoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1169"/>
      <state state_ref="oval:org.mitre.oval:ste:1675"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1822" version="1" check="at least one" comment="/usr/bin/yuvsplittoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1169"/>
      <state state_ref="oval:org.mitre.oval:ste:1674"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1821" version="1" check="at least one" comment="/usr/bin/yuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1168"/>
      <state state_ref="oval:org.mitre.oval:ste:1673"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1820" version="1" check="at least one" comment="/usr/bin/yuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1168"/>
      <state state_ref="oval:org.mitre.oval:ste:1672"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1819" version="1" check="at least one" comment="/usr/bin/yuvtoppm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1168"/>
      <state state_ref="oval:org.mitre.oval:ste:1671"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1818" version="1" check="at least one" comment="/usr/bin/zeisstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1167"/>
      <state state_ref="oval:org.mitre.oval:ste:1670"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1817" version="1" check="at least one" comment="/usr/bin/zeisstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1167"/>
      <state state_ref="oval:org.mitre.oval:ste:1669"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1816" version="1" check="at least one" comment="/usr/bin/zeisstopnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1167"/>
      <state state_ref="oval:org.mitre.oval:ste:1668"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1815" version="1" check="at least one" comment="/usr/bin/pnmscalefixed is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1166"/>
      <state state_ref="oval:org.mitre.oval:ste:1667"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1814" version="1" check="at least one" comment="/usr/bin/pnmscalefixed is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1166"/>
      <state state_ref="oval:org.mitre.oval:ste:1666"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1813" version="1" check="at least one" comment="/usr/bin/pnmscalefixed is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1166"/>
      <state state_ref="oval:org.mitre.oval:ste:1665"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1812" version="1" check="at least one" comment="/usr/bin/pnmshear is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1165"/>
      <state state_ref="oval:org.mitre.oval:ste:1664"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1811" version="1" check="at least one" comment="/usr/bin/pnmshear is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1165"/>
      <state state_ref="oval:org.mitre.oval:ste:1663"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1810" version="1" check="at least one" comment="/usr/bin/pnmshear is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1165"/>
      <state state_ref="oval:org.mitre.oval:ste:1662"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1809" version="1" check="at least one" comment="/usr/bin/pnmsmooth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1164"/>
      <state state_ref="oval:org.mitre.oval:ste:1661"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1808" version="1" check="at least one" comment="/usr/bin/pnmsmooth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1164"/>
      <state state_ref="oval:org.mitre.oval:ste:1660"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1807" version="1" check="at least one" comment="/usr/bin/pnmsmooth is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1164"/>
      <state state_ref="oval:org.mitre.oval:ste:1659"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1806" version="1" check="at least one" comment="/usr/bin/pnmsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1163"/>
      <state state_ref="oval:org.mitre.oval:ste:1658"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1805" version="1" check="at least one" comment="/usr/bin/pnmsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1163"/>
      <state state_ref="oval:org.mitre.oval:ste:1657"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1804" version="1" check="at least one" comment="/usr/bin/pnmsplit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1163"/>
      <state state_ref="oval:org.mitre.oval:ste:1656"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1803" version="1" check="at least one" comment="/usr/bin/pnmtile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1162"/>
      <state state_ref="oval:org.mitre.oval:ste:1655"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1802" version="1" check="at least one" comment="/usr/bin/pnmtile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1162"/>
      <state state_ref="oval:org.mitre.oval:ste:1654"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1801" version="1" check="at least one" comment="/usr/bin/pnmtile is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1162"/>
      <state state_ref="oval:org.mitre.oval:ste:1653"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1800" version="1" check="at least one" comment="/usr/bin/pnmtoddif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1161"/>
      <state state_ref="oval:org.mitre.oval:ste:1652"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1799" version="1" check="at least one" comment="/usr/bin/pnmtoddif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1161"/>
      <state state_ref="oval:org.mitre.oval:ste:1651"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1798" version="1" check="at least one" comment="/usr/bin/pnmtoddif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1161"/>
      <state state_ref="oval:org.mitre.oval:ste:1650"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1797" version="1" check="at least one" comment="/usr/bin/pnmtofiasco is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1160"/>
      <state state_ref="oval:org.mitre.oval:ste:1649"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1796" version="1" check="at least one" comment="/usr/bin/pnmtofiasco is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1160"/>
      <state state_ref="oval:org.mitre.oval:ste:1648"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1795" version="1" check="at least one" comment="/usr/bin/pnmtofiasco is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1160"/>
      <state state_ref="oval:org.mitre.oval:ste:1647"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1794" version="1" check="at least one" comment="/usr/bin/pnmtofits is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1159"/>
      <state state_ref="oval:org.mitre.oval:ste:1646"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1793" version="1" check="at least one" comment="/usr/bin/pnmtofits is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1159"/>
      <state state_ref="oval:org.mitre.oval:ste:1645"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1792" version="1" check="at least one" comment="/usr/bin/pnmtofits is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1159"/>
      <state state_ref="oval:org.mitre.oval:ste:1644"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1791" version="1" check="at least one" comment="/usr/bin/pnmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1158"/>
      <state state_ref="oval:org.mitre.oval:ste:1643"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1790" version="1" check="at least one" comment="/usr/bin/pnmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1158"/>
      <state state_ref="oval:org.mitre.oval:ste:1642"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1789" version="1" check="at least one" comment="/usr/bin/pnmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1158"/>
      <state state_ref="oval:org.mitre.oval:ste:1641"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1788" version="1" check="at least one" comment="/usr/bin/pnmtopalm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1157"/>
      <state state_ref="oval:org.mitre.oval:ste:1640"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1787" version="1" check="at least one" comment="/usr/bin/pnmtopalm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1157"/>
      <state state_ref="oval:org.mitre.oval:ste:1639"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1786" version="1" check="at least one" comment="/usr/bin/pnmtopalm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1157"/>
      <state state_ref="oval:org.mitre.oval:ste:1638"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1785" version="1" check="at least one" comment="/usr/bin/pnmtoplainpnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1156"/>
      <state state_ref="oval:org.mitre.oval:ste:1637"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1784" version="1" check="at least one" comment="/usr/bin/pnmtoplainpnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1156"/>
      <state state_ref="oval:org.mitre.oval:ste:1636"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1783" version="1" check="at least one" comment="/usr/bin/pnmtoplainpnm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1156"/>
      <state state_ref="oval:org.mitre.oval:ste:1635"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1782" version="1" check="at least one" comment="/usr/bin/pnmtopng is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1155"/>
      <state state_ref="oval:org.mitre.oval:ste:1634"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1781" version="1" check="at least one" comment="/usr/bin/pnmtopng is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1155"/>
      <state state_ref="oval:org.mitre.oval:ste:1633"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1780" version="1" check="at least one" comment="/usr/bin/pnmtopng is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1155"/>
      <state state_ref="oval:org.mitre.oval:ste:1632"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1779" version="1" check="at least one" comment="/usr/bin/pnmtops is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1154"/>
      <state state_ref="oval:org.mitre.oval:ste:1631"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1778" version="1" check="at least one" comment="/usr/bin/pnmtops is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1154"/>
      <state state_ref="oval:org.mitre.oval:ste:1630"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1777" version="1" check="at least one" comment="/usr/bin/pnmtops is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1154"/>
      <state state_ref="oval:org.mitre.oval:ste:1629"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1776" version="1" check="at least one" comment="/usr/bin/pnmtorast is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1153"/>
      <state state_ref="oval:org.mitre.oval:ste:1628"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1775" version="1" check="at least one" comment="/usr/bin/pnmtorast is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1153"/>
      <state state_ref="oval:org.mitre.oval:ste:1627"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1774" version="1" check="at least one" comment="/usr/bin/pnmtorast is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1153"/>
      <state state_ref="oval:org.mitre.oval:ste:1626"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1773" version="1" check="at least one" comment="/usr/bin/pnmtorle is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1152"/>
      <state state_ref="oval:org.mitre.oval:ste:1625"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1772" version="1" check="at least one" comment="/usr/bin/pnmtorle is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1152"/>
      <state state_ref="oval:org.mitre.oval:ste:1624"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1771" version="1" check="at least one" comment="/usr/bin/pnmtorle is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1152"/>
      <state state_ref="oval:org.mitre.oval:ste:1623"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1770" version="1" check="at least one" comment="/usr/bin/pnmtosgi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1151"/>
      <state state_ref="oval:org.mitre.oval:ste:1622"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1769" version="1" check="at least one" comment="/usr/bin/pnmtosgi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1151"/>
      <state state_ref="oval:org.mitre.oval:ste:1621"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1768" version="1" check="at least one" comment="/usr/bin/pnmtosgi is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1151"/>
      <state state_ref="oval:org.mitre.oval:ste:1620"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1767" version="1" check="at least one" comment="/usr/bin/pnmtosir is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1150"/>
      <state state_ref="oval:org.mitre.oval:ste:1619"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1766" version="1" check="at least one" comment="/usr/bin/pnmtosir is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1150"/>
      <state state_ref="oval:org.mitre.oval:ste:1618"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1765" version="1" check="at least one" comment="/usr/bin/pnmtosir is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1150"/>
      <state state_ref="oval:org.mitre.oval:ste:1617"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1764" version="1" check="at least one" comment="/usr/bin/pnmtotiff is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1149"/>
      <state state_ref="oval:org.mitre.oval:ste:1616"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1763" version="1" check="at least one" comment="/usr/bin/pnmtotiff is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1149"/>
      <state state_ref="oval:org.mitre.oval:ste:1615"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1762" version="1" check="at least one" comment="/usr/bin/pnmtotiff is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1149"/>
      <state state_ref="oval:org.mitre.oval:ste:1614"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1761" version="1" check="at least one" comment="/usr/bin/pnmtotiffcmyk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1148"/>
      <state state_ref="oval:org.mitre.oval:ste:1613"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1760" version="1" check="at least one" comment="/usr/bin/pnmtotiffcmyk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1148"/>
      <state state_ref="oval:org.mitre.oval:ste:1612"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1759" version="1" check="at least one" comment="/usr/bin/pnmtotiffcmyk is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1148"/>
      <state state_ref="oval:org.mitre.oval:ste:1611"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1758" version="1" check="at least one" comment="/usr/bin/pnmtoxwd is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1147"/>
      <state state_ref="oval:org.mitre.oval:ste:1610"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1757" version="1" check="at least one" comment="/usr/bin/pnmtoxwd is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1147"/>
      <state state_ref="oval:org.mitre.oval:ste:1609"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1756" version="1" check="at least one" comment="/usr/bin/pnmtoxwd is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1147"/>
      <state state_ref="oval:org.mitre.oval:ste:1608"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1755" version="1" check="at least one" comment="/usr/bin/ppm3d is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1146"/>
      <state state_ref="oval:org.mitre.oval:ste:1607"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1754" version="1" check="at least one" comment="/usr/bin/ppm3d is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1146"/>
      <state state_ref="oval:org.mitre.oval:ste:1606"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1753" version="1" check="at least one" comment="/usr/bin/ppm3d is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1146"/>
      <state state_ref="oval:org.mitre.oval:ste:1605"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1752" version="1" check="at least one" comment="/usr/bin/ppmbrighten is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1145"/>
      <state state_ref="oval:org.mitre.oval:ste:1604"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1751" version="1" check="at least one" comment="/usr/bin/ppmbrighten is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1145"/>
      <state state_ref="oval:org.mitre.oval:ste:1603"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1750" version="1" check="at least one" comment="/usr/bin/ppmbrighten is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1145"/>
      <state state_ref="oval:org.mitre.oval:ste:1602"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1749" version="1" check="at least one" comment="/usr/bin/ppmchange is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1144"/>
      <state state_ref="oval:org.mitre.oval:ste:1601"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1748" version="1" check="at least one" comment="/usr/bin/ppmchange is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1144"/>
      <state state_ref="oval:org.mitre.oval:ste:1600"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1747" version="1" check="at least one" comment="/usr/bin/ppmchange is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1144"/>
      <state state_ref="oval:org.mitre.oval:ste:1599"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1746" version="1" check="at least one" comment="/usr/bin/ppmcie is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1143"/>
      <state state_ref="oval:org.mitre.oval:ste:1598"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1745" version="1" check="at least one" comment="/usr/bin/ppmcie is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1143"/>
      <state state_ref="oval:org.mitre.oval:ste:1597"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1744" version="1" check="at least one" comment="/usr/bin/ppmcie is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1143"/>
      <state state_ref="oval:org.mitre.oval:ste:1596"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1743" version="1" check="at least one" comment="/usr/bin/ppmcolormask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1142"/>
      <state state_ref="oval:org.mitre.oval:ste:1595"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1742" version="1" check="at least one" comment="/usr/bin/ppmcolormask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1142"/>
      <state state_ref="oval:org.mitre.oval:ste:1594"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1741" version="1" check="at least one" comment="/usr/bin/ppmcolormask is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1142"/>
      <state state_ref="oval:org.mitre.oval:ste:1593"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1740" version="1" check="at least one" comment="/usr/bin/ppmcolors is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1141"/>
      <state state_ref="oval:org.mitre.oval:ste:1592"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1739" version="1" check="at least one" comment="/usr/bin/ppmcolors is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1141"/>
      <state state_ref="oval:org.mitre.oval:ste:1591"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1738" version="1" check="at least one" comment="/usr/bin/ppmcolors is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1141"/>
      <state state_ref="oval:org.mitre.oval:ste:1590"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1737" version="1" check="at least one" comment="/usr/bin/ppmdim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1140"/>
      <state state_ref="oval:org.mitre.oval:ste:1589"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1736" version="1" check="at least one" comment="/usr/bin/ppmdim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1140"/>
      <state state_ref="oval:org.mitre.oval:ste:1588"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1735" version="1" check="at least one" comment="/usr/bin/ppmdim is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1140"/>
      <state state_ref="oval:org.mitre.oval:ste:1587"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1734" version="1" check="at least one" comment="/usr/bin/ppmdist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1139"/>
      <state state_ref="oval:org.mitre.oval:ste:1586"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1733" version="1" check="at least one" comment="/usr/bin/ppmdist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1139"/>
      <state state_ref="oval:org.mitre.oval:ste:1585"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1732" version="1" check="at least one" comment="/usr/bin/ppmdist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1139"/>
      <state state_ref="oval:org.mitre.oval:ste:1584"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1731" version="1" check="at least one" comment="/usr/bin/ppmdither is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1138"/>
      <state state_ref="oval:org.mitre.oval:ste:1583"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1730" version="1" check="at least one" comment="/usr/bin/ppmdither is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1138"/>
      <state state_ref="oval:org.mitre.oval:ste:1582"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1729" version="1" check="at least one" comment="/usr/bin/ppmdither is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1138"/>
      <state state_ref="oval:org.mitre.oval:ste:1581"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1728" version="1" check="at least one" comment="/usr/bin/ppmflash is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1137"/>
      <state state_ref="oval:org.mitre.oval:ste:1580"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1727" version="1" check="at least one" comment="/usr/bin/ppmflash is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1137"/>
      <state state_ref="oval:org.mitre.oval:ste:1579"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1726" version="1" check="at least one" comment="/usr/bin/ppmflash is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1137"/>
      <state state_ref="oval:org.mitre.oval:ste:1578"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1725" version="1" check="at least one" comment="/usr/bin/ppmforge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1136"/>
      <state state_ref="oval:org.mitre.oval:ste:1577"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1724" version="1" check="at least one" comment="/usr/bin/ppmforge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1136"/>
      <state state_ref="oval:org.mitre.oval:ste:1576"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1723" version="1" check="at least one" comment="/usr/bin/ppmforge is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1136"/>
      <state state_ref="oval:org.mitre.oval:ste:1575"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1722" version="1" check="at least one" comment="/usr/bin/ppmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1135"/>
      <state state_ref="oval:org.mitre.oval:ste:1574"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1721" version="1" check="at least one" comment="/usr/bin/ppmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1135"/>
      <state state_ref="oval:org.mitre.oval:ste:1573"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1720" version="1" check="at least one" comment="/usr/bin/ppmhist is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1135"/>
      <state state_ref="oval:org.mitre.oval:ste:1572"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1719" version="1" check="at least one" comment="/usr/bin/ppmlabel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1134"/>
      <state state_ref="oval:org.mitre.oval:ste:1571"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1718" version="1" check="at least one" comment="/usr/bin/ppmlabel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1134"/>
      <state state_ref="oval:org.mitre.oval:ste:1570"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1717" version="1" check="at least one" comment="/usr/bin/ppmlabel is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1134"/>
      <state state_ref="oval:org.mitre.oval:ste:1569"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1716" version="1" check="at least one" comment="/usr/bin/ppmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1133"/>
      <state state_ref="oval:org.mitre.oval:ste:1568"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1715" version="1" check="at least one" comment="/usr/bin/ppmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1133"/>
      <state state_ref="oval:org.mitre.oval:ste:1567"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1714" version="1" check="at least one" comment="/usr/bin/ppmmake is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1133"/>
      <state state_ref="oval:org.mitre.oval:ste:1566"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1713" version="1" check="at least one" comment="/usr/bin/ppmmix is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1132"/>
      <state state_ref="oval:org.mitre.oval:ste:1565"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1712" version="1" check="at least one" comment="/usr/bin/ppmmix is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1132"/>
      <state state_ref="oval:org.mitre.oval:ste:1564"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1711" version="1" check="at least one" comment="/usr/bin/ppmmix is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1132"/>
      <state state_ref="oval:org.mitre.oval:ste:1563"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1710" version="1" check="at least one" comment="/usr/bin/ppmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1131"/>
      <state state_ref="oval:org.mitre.oval:ste:1562"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1709" version="1" check="at least one" comment="/usr/bin/ppmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1131"/>
      <state state_ref="oval:org.mitre.oval:ste:1561"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1708" version="1" check="at least one" comment="/usr/bin/ppmnorm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1131"/>
      <state state_ref="oval:org.mitre.oval:ste:1560"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1707" version="1" check="at least one" comment="/usr/bin/ppmntsc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1130"/>
      <state state_ref="oval:org.mitre.oval:ste:1559"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1706" version="1" check="at least one" comment="/usr/bin/ppmntsc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1130"/>
      <state state_ref="oval:org.mitre.oval:ste:1558"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1705" version="1" check="at least one" comment="/usr/bin/ppmntsc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1130"/>
      <state state_ref="oval:org.mitre.oval:ste:1557"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1704" version="1" check="at least one" comment="/usr/bin/ppmpat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1129"/>
      <state state_ref="oval:org.mitre.oval:ste:1556"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1703" version="1" check="at least one" comment="/usr/bin/ppmpat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1129"/>
      <state state_ref="oval:org.mitre.oval:ste:1555"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1702" version="1" check="at least one" comment="/usr/bin/ppmpat is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1129"/>
      <state state_ref="oval:org.mitre.oval:ste:1554"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1701" version="1" check="at least one" comment="/usr/bin/ppmquant is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1128"/>
      <state state_ref="oval:org.mitre.oval:ste:1553"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1700" version="1" check="at least one" comment="/usr/bin/ppmquant is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1128"/>
      <state state_ref="oval:org.mitre.oval:ste:1552"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1699" version="1" check="at least one" comment="/usr/bin/ppmquant is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1128"/>
      <state state_ref="oval:org.mitre.oval:ste:1551"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1698" version="1" check="at least one" comment="/usr/bin/ppmqvga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1127"/>
      <state state_ref="oval:org.mitre.oval:ste:1550"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1697" version="1" check="at least one" comment="/usr/bin/ppmqvga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1127"/>
      <state state_ref="oval:org.mitre.oval:ste:1549"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1696" version="1" check="at least one" comment="/usr/bin/ppmqvga is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1127"/>
      <state state_ref="oval:org.mitre.oval:ste:1548"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1695" version="1" check="at least one" comment="/usr/bin/ppmrelief is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1126"/>
      <state state_ref="oval:org.mitre.oval:ste:1547"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1694" version="1" check="at least one" comment="/usr/bin/ppmrelief is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1126"/>
      <state state_ref="oval:org.mitre.oval:ste:1546"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1693" version="1" check="at least one" comment="/usr/bin/ppmrelief is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1126"/>
      <state state_ref="oval:org.mitre.oval:ste:1545"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1692" version="1" check="at least one" comment="/usr/bin/ppmshift is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1125"/>
      <state state_ref="oval:org.mitre.oval:ste:1544"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1691" version="1" check="at least one" comment="/usr/bin/ppmshift is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1125"/>
      <state state_ref="oval:org.mitre.oval:ste:1543"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1690" version="1" check="at least one" comment="/usr/bin/ppmshift is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1125"/>
      <state state_ref="oval:org.mitre.oval:ste:1542"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1689" version="1" check="at least one" comment="/usr/bin/ppmspread is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1124"/>
      <state state_ref="oval:org.mitre.oval:ste:1541"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1688" version="1" check="at least one" comment="/usr/bin/ppmspread is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1124"/>
      <state state_ref="oval:org.mitre.oval:ste:1540"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1687" version="1" check="at least one" comment="/usr/bin/ppmspread is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1124"/>
      <state state_ref="oval:org.mitre.oval:ste:1539"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1686" version="1" check="at least one" comment="/usr/bin/ppmtoacad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1123"/>
      <state state_ref="oval:org.mitre.oval:ste:1538"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1685" version="1" check="at least one" comment="/usr/bin/ppmtoacad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1123"/>
      <state state_ref="oval:org.mitre.oval:ste:1537"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1684" version="1" check="at least one" comment="/usr/bin/ppmtoacad is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1123"/>
      <state state_ref="oval:org.mitre.oval:ste:1536"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1683" version="1" check="at least one" comment="/usr/bin/ppmtobmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1122"/>
      <state state_ref="oval:org.mitre.oval:ste:1535"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1682" version="1" check="at least one" comment="/usr/bin/ppmtobmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1122"/>
      <state state_ref="oval:org.mitre.oval:ste:1534"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1681" version="1" check="at least one" comment="/usr/bin/ppmtobmp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1122"/>
      <state state_ref="oval:org.mitre.oval:ste:1533"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1680" version="1" check="at least one" comment="/usr/bin/ppmtoeyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1121"/>
      <state state_ref="oval:org.mitre.oval:ste:1532"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1679" version="1" check="at least one" comment="/usr/bin/ppmtoeyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1121"/>
      <state state_ref="oval:org.mitre.oval:ste:1531"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1678" version="1" check="at least one" comment="/usr/bin/ppmtoeyuv is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1121"/>
      <state state_ref="oval:org.mitre.oval:ste:1530"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1677" version="1" check="at least one" comment="/usr/bin/ppmtogif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1120"/>
      <state state_ref="oval:org.mitre.oval:ste:1529"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1676" version="1" check="at least one" comment="/usr/bin/ppmtogif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1120"/>
      <state state_ref="oval:org.mitre.oval:ste:1528"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1675" version="1" check="at least one" comment="/usr/bin/ppmtogif is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1120"/>
      <state state_ref="oval:org.mitre.oval:ste:1527"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1674" version="1" check="at least one" comment="/usr/bin/ppmtoicr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1119"/>
      <state state_ref="oval:org.mitre.oval:ste:1526"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1673" version="1" check="at least one" comment="/usr/bin/ppmtoicr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1119"/>
      <state state_ref="oval:org.mitre.oval:ste:1525"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1672" version="1" check="at least one" comment="/usr/bin/ppmtoicr is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1119"/>
      <state state_ref="oval:org.mitre.oval:ste:1524"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1671" version="1" check="at least one" comment="/usr/bin/ppmtoilbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1118"/>
      <state state_ref="oval:org.mitre.oval:ste:1523"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1670" version="1" check="at least one" comment="/usr/bin/ppmtoilbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1118"/>
      <state state_ref="oval:org.mitre.oval:ste:1522"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1669" version="1" check="at least one" comment="/usr/bin/ppmtoilbm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1118"/>
      <state state_ref="oval:org.mitre.oval:ste:1521"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1668" version="1" check="at least one" comment="/usr/bin/ppmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1117"/>
      <state state_ref="oval:org.mitre.oval:ste:1520"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1667" version="1" check="at least one" comment="/usr/bin/ppmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1117"/>
      <state state_ref="oval:org.mitre.oval:ste:1519"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1666" version="1" check="at least one" comment="/usr/bin/ppmtojpeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1117"/>
      <state state_ref="oval:org.mitre.oval:ste:1518"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1665" version="1" check="at least one" comment="/usr/bin/ppmtoleaf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1116"/>
      <state state_ref="oval:org.mitre.oval:ste:1517"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1664" version="1" check="at least one" comment="/usr/bin/ppmtoleaf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1116"/>
      <state state_ref="oval:org.mitre.oval:ste:1516"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1663" version="1" check="at least one" comment="/usr/bin/ppmtoleaf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1116"/>
      <state state_ref="oval:org.mitre.oval:ste:1515"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1662" version="1" check="at least one" comment="/usr/bin/ppmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1115"/>
      <state state_ref="oval:org.mitre.oval:ste:1514"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1661" version="1" check="at least one" comment="/usr/bin/ppmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1115"/>
      <state state_ref="oval:org.mitre.oval:ste:1513"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1660" version="1" check="at least one" comment="/usr/bin/ppmtolj is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1115"/>
      <state state_ref="oval:org.mitre.oval:ste:1512"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1659" version="1" check="at least one" comment="/usr/bin/ppmtomitsu is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1114"/>
      <state state_ref="oval:org.mitre.oval:ste:1511"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1658" version="1" check="at least one" comment="/usr/bin/ppmtomitsu is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1114"/>
      <state state_ref="oval:org.mitre.oval:ste:1510"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1657" version="1" check="at least one" comment="/usr/bin/ppmtomitsu is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1114"/>
      <state state_ref="oval:org.mitre.oval:ste:1509"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1656" version="1" check="at least one" comment="/usr/bin/ppmtompeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1113"/>
      <state state_ref="oval:org.mitre.oval:ste:1508"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1655" version="1" check="at least one" comment="/usr/bin/ppmtompeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1113"/>
      <state state_ref="oval:org.mitre.oval:ste:1507"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1654" version="1" check="at least one" comment="/usr/bin/ppmtompeg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1113"/>
      <state state_ref="oval:org.mitre.oval:ste:1506"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1653" version="1" check="at least one" comment="/usr/bin/ppmtoneo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1112"/>
      <state state_ref="oval:org.mitre.oval:ste:1505"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1652" version="1" check="at least one" comment="/usr/bin/ppmtoneo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1112"/>
      <state state_ref="oval:org.mitre.oval:ste:1504"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1651" version="1" check="at least one" comment="/usr/bin/ppmtoneo is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1112"/>
      <state state_ref="oval:org.mitre.oval:ste:1503"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1650" version="1" check="at least one" comment="/usr/bin/ppmtopcx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1111"/>
      <state state_ref="oval:org.mitre.oval:ste:1502"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1649" version="1" check="at least one" comment="/usr/bin/ppmtopcx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1111"/>
      <state state_ref="oval:org.mitre.oval:ste:1501"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1648" version="1" check="at least one" comment="/usr/bin/ppmtopcx is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1111"/>
      <state state_ref="oval:org.mitre.oval:ste:1500"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1647" version="1" check="at least one" comment="/usr/bin/ppmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1110"/>
      <state state_ref="oval:org.mitre.oval:ste:1499"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1646" version="1" check="at least one" comment="/usr/bin/ppmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1110"/>
      <state state_ref="oval:org.mitre.oval:ste:1498"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1645" version="1" check="at least one" comment="/usr/bin/ppmtopgm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1110"/>
      <state state_ref="oval:org.mitre.oval:ste:1497"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1644" version="1" check="at least one" comment="/usr/bin/ppmtopi1 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1109"/>
      <state state_ref="oval:org.mitre.oval:ste:1496"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1643" version="1" check="at least one" comment="/usr/bin/ppmtopi1 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1109"/>
      <state state_ref="oval:org.mitre.oval:ste:1495"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1642" version="1" check="at least one" comment="/usr/bin/ppmtopi1 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1109"/>
      <state state_ref="oval:org.mitre.oval:ste:1494"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2321" version="1" check="at least one" comment="pwlib version is less than 1.4.7-4.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1338"/>
      <state state_ref="oval:org.mitre.oval:ste:2173"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2320" version="1" check="at least one" comment="a program is listening on TCP or UDP port 1720" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1337"/>
      <state state_ref="oval:org.mitre.oval:ste:2172"/>
    </inetlisteningservers_test>
    <file_test id="oval:org.mitre.oval:tst:2322" version="1" check="at least one" comment="the version of wins.exe is less than 5.2.3790.99" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:2174"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2323" version="1" check="at least one" comment="the version of wins.exe is less than 4.0.1381.33554" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:2175"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2324" version="1" check="at least one" comment="the version of wins.exe is less than 4.0.1381.7255" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:2176"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2969" version="1" check="at least one" comment="Patch 107893-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:301"/>
      <state state_ref="oval:org.mitre.oval:ste:2783"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2325" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.2.3790.88" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:2177"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2326" version="1" check="at least one" comment="the version of Winword.exe is less than 10.0.6775.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2178"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2329" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.119" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:2181"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2328" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.1274" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:2180"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2330" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.0.2195.6824" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:2182"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2970" version="1" check="at least one" comment="Patch 112846-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1699"/>
      <state state_ref="oval:org.mitre.oval:ste:2784"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2340" version="1" check="all" comment="netman.dll is less than 5.2.3790.2516" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:658"/>
      <state state_ref="oval:org.mitre.oval:ste:2191"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2344" version="1" check="at least one" comment="Patch PHCO_29269 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1344"/>
      <state state_ref="oval:org.mitre.oval:ste:2195"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2343" version="1" check="at least one" comment="Patch PHCO_30275 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1343"/>
      <state state_ref="oval:org.mitre.oval:ste:2194"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2342" version="1" check="at least one" comment="Patch PHCO_32181 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1342"/>
      <state state_ref="oval:org.mitre.oval:ste:2193"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2351" version="1" check="all" comment="the patch KB896428 for Services for UNIX is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1346"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2350" version="1" check="all" comment="the version of telnet.exe is less than 5.3000.2073.13" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:816"/>
      <state state_ref="oval:org.mitre.oval:ste:2201"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2349" version="1" check="at least one" comment="the software Services for UNIX is installed and the version is 2.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1345"/>
      <state state_ref="oval:org.mitre.oval:ste:2200"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2348" version="1" check="at least one" comment="the software Services for UNIX is installed and the version is 3.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1345"/>
      <state state_ref="oval:org.mitre.oval:ste:2199"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2347" version="1" check="all" comment="the version of telnet.exe is less than 7.0.1701.44" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:816"/>
      <state state_ref="oval:org.mitre.oval:ste:2198"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2346" version="1" check="at least one" comment="the software Services for UNIX is installed and the version is 3.5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1345"/>
      <state state_ref="oval:org.mitre.oval:ste:2197"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2345" version="1" check="all" comment="the version of telnet.exe is less than 8.0.1969.33" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:816"/>
      <state state_ref="oval:org.mitre.oval:ste:2196"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3457" version="1" check="at least one" comment="the version of umpnpmgr.dll is less than 5.2.3790.360" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2048"/>
      <state state_ref="oval:org.mitre.oval:ste:3122"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2971" version="1" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1631"/>
      <state state_ref="oval:org.mitre.oval:ste:2785"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2355" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.160" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:2205"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2357" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.0.2195.6987" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:2207"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2362" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 2000.85.1025.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2212"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2361" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.85.1025.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2211"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2360" version="1" check="at least one" comment="the patch q832483 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1350"/>
      <state state_ref="oval:org.mitre.oval:ste:2210"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2366" version="1" check="at least one" comment="the version of mscms.dll is less than 5.2.3790.2476" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:745"/>
      <state state_ref="oval:org.mitre.oval:ste:2216"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:2373" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1356"/>
      <state state_ref="oval:org.mitre.oval:ste:2223"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2372" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1355"/>
      <state state_ref="oval:org.mitre.oval:ste:2222"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2371" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1354"/>
      <state state_ref="oval:org.mitre.oval:ste:2221"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2370" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1353"/>
      <state state_ref="oval:org.mitre.oval:ste:2220"/>
    </swlist_test>
    <uname_test id="oval:org.mitre.oval:tst:2369" version="1" check="all" comment="HP Release B.10.01" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2219"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:2368" version="1" check="all" comment="HP Release B.10.10" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2218"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:2367" version="1" check="at least one" comment="Patch PHNE_23947 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1352"/>
      <state state_ref="oval:org.mitre.oval:ste:2217"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2374" version="1" check="at least one" comment="Patch PHNE_33790 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1357"/>
      <state state_ref="oval:org.mitre.oval:ste:2224"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2973" version="1" check="at least one" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1641"/>
      <state state_ref="oval:org.mitre.oval:ste:2787"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3363" version="1" check="at least one" comment="Patch 120955-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2616"/>
      <state state_ref="oval:org.mitre.oval:ste:3553"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2384" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.81.9002.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2233"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2383" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 2000.81.9002.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2232"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2381" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.81.9042.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2230"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2380" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 2000.81.9042.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2229"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:269" version="1" check="at least one" comment="Internet Explorer 6 Service Pack 2 for XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:267"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:268" version="1" check="at least one" comment="machine has followed the GDR update path and mshtml.dll is less than  6.0.2900.2523" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:266"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:267" version="1" check="at least one" comment="machine has followed the QFE update path and mshtml.dll is less than  6.0.2900.2524" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:265"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:266" version="1" check="at least one" comment="the patch kb834707  is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:246"/>
      <state state_ref="oval:org.mitre.oval:ste:264"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:2974" version="1" check="at least one" comment="Patch 106934-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1701"/>
      <state state_ref="oval:org.mitre.oval:ste:2788"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3902" version="1" check="at least one" comment="Perl 5.8.0 (revision F or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2356"/>
      <state state_ref="oval:org.mitre.oval:ste:3557"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3847" version="1" check="at least one" comment="Perl 5.8.3,revision A is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2426"/>
      <state state_ref="oval:org.mitre.oval:ste:3790"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3635" version="1" check="at least one" comment="Perl 5.8.2,revision E or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1863"/>
      <state state_ref="oval:org.mitre.oval:ste:3165"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3419" version="1" check="at least one" comment="Perl 5.6.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2267"/>
      <state state_ref="oval:org.mitre.oval:ste:3647"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3226" version="1" check="at least one" comment="Perl 5.8.2,revision C or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2172"/>
      <state state_ref="oval:org.mitre.oval:ste:3104"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:2389" version="1" check="at least one" comment="the version of Imekr70.ime is less than 7.0.8002.0 (Office 2003 and Accessories)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1366"/>
      <state state_ref="oval:org.mitre.oval:ste:2237"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:4066" version="1" check="at least one" comment="Patch 115168-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1845"/>
      <state state_ref="oval:org.mitre.oval:ste:3131"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:4043" version="1" check="at least one" comment="Patch 112238-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1830"/>
      <state state_ref="oval:org.mitre.oval:ste:3692"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3873" version="1" check="at least one" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2655"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:3824" version="1" check="at least one" comment="Patch 112908-15 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2309"/>
      <state state_ref="oval:org.mitre.oval:ste:3372"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3544" version="1" check="at least one" comment="Patch 112536-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1847"/>
      <state state_ref="oval:org.mitre.oval:ste:3437"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3514" version="1" check="at least one" comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2213"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:3509" version="1" check="at least one" comment="Patch 112390-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2709"/>
      <state state_ref="oval:org.mitre.oval:ste:3614"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3498" version="1" check="at least one" comment="Patch 112537-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2196"/>
      <state state_ref="oval:org.mitre.oval:ste:3009"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3369" version="1" check="at least one" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2138"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:3366" version="1" check="at least one" comment="Patch 112240-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2599"/>
      <state state_ref="oval:org.mitre.oval:ste:3847"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3354" version="1" check="at least one" comment="Patch 112237-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2466"/>
      <state state_ref="oval:org.mitre.oval:ste:2964"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3192" version="1" check="at least one" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2617"/>
    </package_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.1.2600.1863." id="oval:org.mitre.oval:tst:81" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:139"/>
      <state state_ref="oval:org.mitre.oval:ste:46"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.2745." id="oval:org.mitre.oval:tst:51" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:139"/>
      <state state_ref="oval:org.mitre.oval:ste:119"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.1.2600.2938." id="oval:org.mitre.oval:tst:198" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:139"/>
      <state state_ref="oval:org.mitre.oval:ste:81"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:139"/>
      <state state_ref="oval:org.mitre.oval:ste:163"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.0.2195.7100." id="oval:org.mitre.oval:tst:130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:139"/>
      <state state_ref="oval:org.mitre.oval:ste:10"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2392" version="1" check="at least one" comment="the version of webclnt.dll is less than 5.2.3790.316" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:628"/>
      <state state_ref="oval:org.mitre.oval:ste:2240"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2394" version="1" check="all" comment="gftp rpm is earlier than 1:2.0.14-4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1369"/>
      <state state_ref="oval:org.mitre.oval:ste:2242"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2393" version="1" check="all" comment="gftp is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1368"/>
      <state state_ref="oval:org.mitre.oval:ste:2241"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2397" version="1" check="at least one" comment="the version of Fontsub.dll is less than 5.0.2195.7071" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:668"/>
      <state state_ref="oval:org.mitre.oval:ste:2245"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2396" version="1" check="at least one" comment="the version of T2embed.dll is less than 5.0.2195.7073" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:667"/>
      <state state_ref="oval:org.mitre.oval:ste:2244"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2401" version="1" check="all" comment="ImageMagick RPM earlier than 0:5.5.6-14" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <oval-def:notes>
        <oval-def:note>The ImageMagick-devel, ImageMagick-c++-devel, and ImageMagick-c++ RPMs all require that the exact same version of the ImageMagick RPM is present.  As such, we can test for a vulnerable version of the former alone, rather than testing for the presence of each of these RPMs in particular.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:1371"/>
      <state state_ref="oval:org.mitre.oval:ste:2249"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2976" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.296.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2790"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2404" version="1" check="all" comment="shell32.dll is less than 6.0.3790.2521" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:2252"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2407" version="1" check="at least one" comment="the version of wins.exe is less than 5.0.2195.6870" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:2255"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2406" version="1" check="at least one" comment="the patch kb830352 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1373"/>
      <state state_ref="oval:org.mitre.oval:ste:2254"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:2413" version="1" check="at least one" comment="Patch 112234-11 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1376"/>
      <state state_ref="oval:org.mitre.oval:ste:2261"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2412" version="1" check="at least one" comment="Patch 112234-12 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1376"/>
      <state state_ref="oval:org.mitre.oval:ste:2260"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2411" version="1" check="at least one" comment="Patch 117172-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1375"/>
      <state state_ref="oval:org.mitre.oval:ste:2259"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2410" version="1" check="at least one" comment="Patch 118559-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:607"/>
      <state state_ref="oval:org.mitre.oval:ste:2258"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2983" version="1" check="at least one" comment="File dtspcd exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1703"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2982" version="1" check="at least one" comment="Patch 108949-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:256"/>
      <state state_ref="oval:org.mitre.oval:ste:2796"/>
    </patch_test>
    <inetd_test id="oval:org.mitre.oval:tst:2981" version="1" check="at least one" comment="inetd.conf contains dtspcd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1704"/>
      <state state_ref="oval:org.mitre.oval:ste:2795"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:2980" version="1" check="at least one" comment="File dtspcd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1703"/>
      <state state_ref="oval:org.mitre.oval:ste:2794"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2979" version="1" check="at least one" comment="File dtspcd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1703"/>
      <state state_ref="oval:org.mitre.oval:ste:2793"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2978" version="1" check="at least one" comment="File dtspcd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1703"/>
      <state state_ref="oval:org.mitre.oval:ste:2792"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2416" version="1" check="at least one" comment="the version of Fontsub.dll is less than 5.1.2600.2777" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:668"/>
      <state state_ref="oval:org.mitre.oval:ste:2264"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2415" version="1" check="at least one" comment="the version of T2embed.dll is less than 5.1.2600.2777" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:667"/>
      <state state_ref="oval:org.mitre.oval:ste:2263"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2419" version="2" check="at least one" comment="the version of excel.exe is less than 10.0.5815.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2267"/>
    </file_test>
    <file_test check="all" comment="The version of vbe6.dll is less than 6.4.99.72." id="oval:org.mitre.oval:tst:94" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:148"/>
      <state state_ref="oval:org.mitre.oval:ste:16"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2423" version="1" check="at least one" comment="the version of webclnt.dll is less than 5.1.2600.1790 (XP,SP1)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:628"/>
      <state state_ref="oval:org.mitre.oval:ste:2270"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2430" version="1" check="at least one" comment="the version of user32.dll is less than 4.0.1381.7177" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:2277"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2429" version="1" check="at least one" comment="the version of gdi32.dll is less than 4.0.1381.7177" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:279"/>
      <state state_ref="oval:org.mitre.oval:ste:2276"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2428" version="1" check="at least one" comment="the version of winsrv.dll is less than 4.0.1381.7202" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1382"/>
      <state state_ref="oval:org.mitre.oval:ste:2275"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2427" version="1" check="at least one" comment="the version of win32k.sys is less than 4.0.1381.7207" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:570"/>
      <state state_ref="oval:org.mitre.oval:ste:2274"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2426" version="1" check="at least one" comment="Patch Q328310 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1381"/>
      <state state_ref="oval:org.mitre.oval:ste:2273"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:2986" version="1" check="at least one" comment="Patch 108721-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1707"/>
      <state state_ref="oval:org.mitre.oval:ste:2799"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:271" version="1" check="at least one" comment="the 64-bit WOW version of netdde.exe is less than 5.2.3790.193" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:249"/>
      <state state_ref="oval:org.mitre.oval:ste:269"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:270" version="1" check="at least one" comment="the 64-bit WOW version of nddenb32.dll is less than 5.2.3790.193" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:248"/>
      <state state_ref="oval:org.mitre.oval:ste:268"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2433" version="1" check="all" comment="rh-postgresql-server is earlier than 0:7.3.10-1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1384"/>
      <state state_ref="oval:org.mitre.oval:ste:2279"/>
    </rpminfo_test>
    <file_test check="all" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7098." id="oval:org.mitre.oval:tst:46" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:144"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2448" version="1" check="at least one" comment="Mozilla Thunderbird pre-1.5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1389"/>
      <state state_ref="oval:org.mitre.oval:ste:2293"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2447" version="1" check="at least one" comment="Thunderbird pre-1.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:2292"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:2987" version="1" check="at least one" comment="Patch 110453-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1708"/>
      <state state_ref="oval:org.mitre.oval:ste:2800"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2449" version="1" check="at least one" comment="the version of winword.exe is less than 10.0.5815.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2294"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2451" version="1" check="at least one" comment="ypserv version is less than 2.8-0.9E" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1391"/>
      <state state_ref="oval:org.mitre.oval:ste:2296"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2450" version="1" check="at least one" comment="ypserv is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1390"/>
      <state state_ref="oval:org.mitre.oval:ste:2295"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2455" version="1" check="at least one" comment="xpdf version is less than 2.0.1-11" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1393"/>
      <state state_ref="oval:org.mitre.oval:ste:2300"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2454" version="1" check="at least one" comment="xpdf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1392"/>
      <state state_ref="oval:org.mitre.oval:ste:2299"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2453" version="1" check="at least one" comment="xpdf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1392"/>
      <state state_ref="oval:org.mitre.oval:ste:2298"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2452" version="1" check="at least one" comment="xpdf is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1392"/>
      <state state_ref="oval:org.mitre.oval:ste:2297"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2464" version="1" check="at least one" comment="Patch 109320-17 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:315"/>
      <state state_ref="oval:org.mitre.oval:ste:2308"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2462" version="1" check="at least one" comment="Patch 109321-17 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1398"/>
      <state state_ref="oval:org.mitre.oval:ste:2306"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2461" version="1" check="at least one" comment="Patch 113329-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:314"/>
      <state state_ref="oval:org.mitre.oval:ste:2305"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2460" version="1" check="at least one" comment="Patch 114980-17 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1397"/>
      <state state_ref="oval:org.mitre.oval:ste:2304"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2458" version="1" check="at least one" comment="Patch 120467-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1396"/>
      <state state_ref="oval:org.mitre.oval:ste:2302"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2457" version="1" check="at least one" comment="Patch 120468-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1395"/>
      <state state_ref="oval:org.mitre.oval:ste:2301"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2456" version="1" check="at least one" comment="Target is configured as a print server" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1394"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2467" version="1" check="at least one" comment="xinetd version is less than 2:2.3.11-1.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1400"/>
      <state state_ref="oval:org.mitre.oval:ste:2311"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2466" version="1" check="at least one" comment="xinetd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1399"/>
      <state state_ref="oval:org.mitre.oval:ste:2310"/>
    </inetlisteningservers_test>
    <file_test id="oval:org.mitre.oval:tst:2469" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.0.2195.6823" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:2313"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2468" version="1" check="at least one" comment="the patch kb828028 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1401"/>
      <state state_ref="oval:org.mitre.oval:ste:2312"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3144" version="1" check="at least one" comment="File kcms_configure exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1787"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3143" version="1" check="at least one" comment="File kcms_configure executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1787"/>
      <state state_ref="oval:org.mitre.oval:ste:2940"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3142" version="1" check="at least one" comment="File kcms_configure executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1787"/>
      <state state_ref="oval:org.mitre.oval:ste:2939"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3141" version="1" check="at least one" comment="File kcms_configure executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1787"/>
      <state state_ref="oval:org.mitre.oval:ste:2938"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2989" version="1" check="at least one" comment="Patch 107337-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:431"/>
      <state state_ref="oval:org.mitre.oval:ste:2802"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2471" version="1" check="at least one" comment="Patch PHNE_30983 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1403"/>
      <state state_ref="oval:org.mitre.oval:ste:2315"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2470" version="1" check="at least one" comment="Patch PHNE_31732 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1402"/>
      <state state_ref="oval:org.mitre.oval:ste:2314"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2474" version="1" check="all" comment="mikmod RPM prior to 0:3.1.6-22.EL3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1406"/>
      <state state_ref="oval:org.mitre.oval:ste:2318"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2473" version="1" check="all" comment="/usr/bin/mikmod is executable by any user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1405"/>
      <state state_ref="oval:org.mitre.oval:ste:2317"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2476" version="1" check="at least one" comment="the version of Llssrv.exe is less than 4.0.1381.33632" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:277"/>
      <state state_ref="oval:org.mitre.oval:ste:2320"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:2481" version="1" check="at least one" comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1412"/>
      <state state_ref="oval:org.mitre.oval:ste:2325"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2480" version="1" check="at least one" comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1411"/>
      <state state_ref="oval:org.mitre.oval:ste:2324"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2479" version="1" check="at least one" comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1410"/>
      <state state_ref="oval:org.mitre.oval:ste:2323"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2478" version="1" check="at least one" comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1409"/>
      <state state_ref="oval:org.mitre.oval:ste:2322"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:2991" version="1" check="at least one" comment="File %windir%\system32\netlogon.dll version is less than 5.0.893.1105" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1640"/>
      <state state_ref="oval:org.mitre.oval:ste:2804"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:272" version="1" check="at least one" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.2800.1584" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:250"/>
      <state state_ref="oval:org.mitre.oval:ste:270"/>
    </file_test>
    <file_test check="all" comment="The version of mmc.exe is less than 5.0.2195.7102." id="oval:org.mitre.oval:tst:193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:194"/>
      <state state_ref="oval:org.mitre.oval:ste:186"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2484" version="2" check="at least one" comment="the version of excel.exe is less than 9.0.0.8216" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2328"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2487" version="1" check="at least one" comment="vsftpd version is less than 1.1.3-8" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1417"/>
      <state state_ref="oval:org.mitre.oval:ste:2330"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2486" version="1" check="at least one" comment="vsftpd is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1416"/>
      <state state_ref="oval:org.mitre.oval:ste:2329"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2489" version="1" check="at least one" comment="up2date version is less than 3.1.23.1-5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1419"/>
      <state state_ref="oval:org.mitre.oval:ste:2331"/>
    </rpminfo_test>
    <process_test id="oval:org.mitre.oval:tst:2488" version="1" check="at least one" comment="rhnsd is running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1418"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:2992" version="1" check="at least one" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1711"/>
      <state state_ref="oval:org.mitre.oval:ste:2805"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2491" version="1" check="at least one" comment="the version of Mapi32.dll is less than 5.5.2658.34" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:837"/>
      <state state_ref="oval:org.mitre.oval:ste:2332"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2494" version="1" check="all" comment="sysreport RPM earlier than 0:1.3.7.2-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1421"/>
      <state state_ref="oval:org.mitre.oval:ste:2335"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2493" version="1" check="all" comment="/tmp is world-writable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oval-def:notes>
        <oval-def:note>For "/tmp is readable by non-root users," use a compound test.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:1420"/>
      <state state_ref="oval:org.mitre.oval:ste:2334"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2995" version="1" check="at least one" comment="File mibiisa exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1713"/>
    </file_test>
    <process_test id="oval:org.mitre.oval:tst:2993" version="1" check="at least one" comment="mibiisa running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1712"/>
    </process_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2498" version="1" check="at least one" comment="unzip version is less than 5.50-33" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1423"/>
      <state state_ref="oval:org.mitre.oval:ste:2339"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2497" version="1" check="at least one" comment="/usr/bin/unzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1422"/>
      <state state_ref="oval:org.mitre.oval:ste:2338"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2496" version="1" check="at least one" comment="/usr/bin/unzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1422"/>
      <state state_ref="oval:org.mitre.oval:ste:2337"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2495" version="1" check="at least one" comment="/usr/bin/unzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1422"/>
      <state state_ref="oval:org.mitre.oval:ste:2336"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3742" version="1" check="at least one" comment="the version of rdpwd.sys is less than 5.1.2600.1698" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2219"/>
      <state state_ref="oval:org.mitre.oval:ste:3928"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3974" version="1" check="at least one" comment="Patch PHSS_29964 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2784"/>
      <state state_ref="oval:org.mitre.oval:ste:3612"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3831" version="1" check="at least one" comment="Patch PHCO_28848 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1856"/>
      <state state_ref="oval:org.mitre.oval:ste:3793"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3641" version="1" check="at least one" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2161"/>
      <state state_ref="oval:org.mitre.oval:ste:3359"/>
    </swlist_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2499" version="1" check="at least one" comment="squirrelmail version is less than 1.2.11-1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1424"/>
      <state state_ref="oval:org.mitre.oval:ste:2340"/>
    </rpminfo_test>
    <uname_test id="oval:org.mitre.oval:tst:3985" version="1" check="all" comment="HP Release B.10.10" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3450"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:3807" version="1" check="all" comment="HP Release B.10.20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3946"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:3674" version="1" check="at least one" comment="Patch PHCO_23261 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2358"/>
      <state state_ref="oval:org.mitre.oval:ste:3110"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3581" version="1" check="all" comment="HP Release B.10.01" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3134"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:3461" version="1" check="all" comment="HP Release B.10.30" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3213"/>
    </uname_test>
    <swlist_test id="oval:org.mitre.oval:tst:3376" version="1" check="at least one" comment="OS-Core.C2400-UTIL is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1876"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3370" version="1" check="at least one" comment="OS-Core.ADMN-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2208"/>
    </swlist_test>
    <registry_test id="oval:org.mitre.oval:tst:2999" version="1" check="at least one" comment="RAS Phonebook" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1716"/>
      <state state_ref="oval:org.mitre.oval:ste:2810"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2998" version="1" check="at least one" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1711"/>
      <state state_ref="oval:org.mitre.oval:ste:2809"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2997" version="1" check="at least one" comment="Patch Q318138 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1715"/>
      <state state_ref="oval:org.mitre.oval:ste:2808"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3978" version="1" check="at least one" comment="the version of rdpwd.sys is less than 5.2.3790.348" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2219"/>
      <state state_ref="oval:org.mitre.oval:ste:2967"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3429" version="1" check="at least one" comment="Win2K/XP/2003 is patched" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2558"/>
      <state state_ref="oval:org.mitre.oval:ste:3948"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2501" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.327" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2342"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2500" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2440" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2341"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2504" version="1" check="all" comment="the version of telnet.exe is less than 5.2.3790.329" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:816"/>
      <state state_ref="oval:org.mitre.oval:ste:2345"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3147" version="1" check="at least one" comment="cups version is less than 1.1.17-13.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1789"/>
      <state state_ref="oval:org.mitre.oval:ste:2943"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:3146" version="1" check="at least one" comment="cupsd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1788"/>
      <state state_ref="oval:org.mitre.oval:ste:2942"/>
    </inetlisteningservers_test>
    <swlist_test id="oval:org.mitre.oval:tst:2510" version="1" check="at least one" comment="X11.X11-RUN-CL is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1431"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:2509" version="1" check="at least one" comment="Patch PHSS_32109 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1430"/>
      <state state_ref="oval:org.mitre.oval:ste:2350"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2508" version="1" check="at least one" comment="Patch PHSS_30791 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1429"/>
      <state state_ref="oval:org.mitre.oval:ste:2349"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2507" version="1" check="at least one" comment="Patch PHSS_33589 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1428"/>
      <state state_ref="oval:org.mitre.oval:ste:2348"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2506" version="1" check="at least one" comment="Patch PHSS_31833 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1427"/>
      <state state_ref="oval:org.mitre.oval:ste:2347"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2505" version="1" check="at least one" comment="Patch PHSS_32366 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1426"/>
      <state state_ref="oval:org.mitre.oval:ste:2346"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2517" version="1" check="at least one" comment="sendmail version is less than 8.12.8-6.90" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1433"/>
      <state state_ref="oval:org.mitre.oval:ste:2357"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2516" version="1" check="at least one" comment="sendmail is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1432"/>
      <state state_ref="oval:org.mitre.oval:ste:2356"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2518" version="1" check="at least one" comment="sendmail version is less than 8.12.8-9.90" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1434"/>
      <state state_ref="oval:org.mitre.oval:ste:2358"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:2519" version="1" check="at least one" comment="MSN Messenger 6.2.0205 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1435"/>
      <state state_ref="oval:org.mitre.oval:ste:2359"/>
    </registry_test>
    <swlist_test id="oval:org.mitre.oval:tst:3687" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2115"/>
      <state state_ref="oval:org.mitre.oval:ste:3599"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:3428" version="1" check="at least one" comment="Patch PHNE_33414 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1815"/>
      <state state_ref="oval:org.mitre.oval:ste:3294"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:274" version="1" check="at least one" comment="the version of nntpsvc.dll is less than 5.0.2195.6972" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:252"/>
      <state state_ref="oval:org.mitre.oval:ste:272"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:273" version="1" check="at least one" comment="Patch Windows2000-KB883935-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:251"/>
      <state state_ref="oval:org.mitre.oval:ste:271"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:2525" version="1" check="all" comment="Remote Network Server Commands - Usr (SUNWrcmds) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1441"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:2524" version="1" check="all" comment="Patch 118239-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1440"/>
      <state state_ref="oval:org.mitre.oval:ste:2363"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2523" version="1" check="all" comment="Patch 116984-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1439"/>
      <state state_ref="oval:org.mitre.oval:ste:2362"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2522" version="1" check="all" comment="Patch 117455-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1438"/>
      <state state_ref="oval:org.mitre.oval:ste:2361"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:2521" version="1" check="all" comment="in.rwhod is running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1437"/>
    </process_test>
    <registry_test id="oval:org.mitre.oval:tst:2526" version="1" check="at least one" comment="FrontPage Server Extensions 2000 are enabled (WinNT)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1442"/>
    </registry_test>
    <registry_test check="at least one" comment="Publisher 2002 is installed" id="oval:org.mitre.oval:tst:140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:189"/>
    </registry_test>
    <file_test check="all" comment="the version of mspub.exe is less than 9.0.0.8930" id="oval:org.mitre.oval:tst:36" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:94"/>
      <state state_ref="oval:org.mitre.oval:ste:100"/>
    </file_test>
    <file_test check="all" comment="the version of mspub.exe is less than 11.0.8103.0" id="oval:org.mitre.oval:tst:29" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:94"/>
      <state state_ref="oval:org.mitre.oval:ste:44"/>
    </file_test>
    <file_test check="all" comment="the version of mspub.exe is less than 10.0.6815.0" id="oval:org.mitre.oval:tst:168" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:94"/>
      <state state_ref="oval:org.mitre.oval:ste:75"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3002" version="1" check="at least one" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:2813"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3001" version="1" check="at least one" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1718"/>
      <state state_ref="oval:org.mitre.oval:ste:2812"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2527" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.274" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:2364"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2536" version="1" check="at least one" comment="the version of msjava.dll is less than 5.0.3809.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1446"/>
      <state state_ref="oval:org.mitre.oval:ste:2371"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2537" version="1" check="all" comment="cdosys.dll is less than 6.5.6756.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:661"/>
      <state state_ref="oval:org.mitre.oval:ste:2372"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2541" version="1" check="at least one" comment="the version of wkssvc.dll is less than 5.00.2195.6862" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1448"/>
      <state state_ref="oval:org.mitre.oval:ste:2376"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2540" version="1" check="at least one" comment="the patch q828748 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1447"/>
      <state state_ref="oval:org.mitre.oval:ste:2375"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2543" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2900.2620" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:2377"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2549" version="1" check="at least one" comment="sendmail version is less than 8.12.8-5.90" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1452"/>
      <state state_ref="oval:org.mitre.oval:ste:2383"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2548" version="1" check="at least one" comment="sendmail is Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2382"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2547" version="1" check="at least one" comment="sendmail is Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2381"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2546" version="1" check="at least one" comment="sendmail is Set-UID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2380"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2545" version="1" check="at least one" comment="sendmail is Set-GID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1451"/>
      <state state_ref="oval:org.mitre.oval:ste:2379"/>
    </file_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2544" version="1" check="at least one" comment="sendmail listening" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1450"/>
      <state state_ref="oval:org.mitre.oval:ste:2378"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2557" version="1" check="at least one" comment="wl version is less than 2.10.1-1.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1456"/>
      <state state_ref="oval:org.mitre.oval:ste:2391"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2556" version="1" check="at least one" comment="wl-xemacs version is less than 2.10.1-1.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1455"/>
      <state state_ref="oval:org.mitre.oval:ste:2390"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2555" version="1" check="at least one" comment="/usr/bin/emacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1454"/>
      <state state_ref="oval:org.mitre.oval:ste:2389"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2554" version="1" check="at least one" comment="/usr/bin/emacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1454"/>
      <state state_ref="oval:org.mitre.oval:ste:2388"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2553" version="1" check="at least one" comment="/usr/bin/emacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1454"/>
      <state state_ref="oval:org.mitre.oval:ste:2387"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2552" version="1" check="at least one" comment="/usr/bin/xemacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1453"/>
      <state state_ref="oval:org.mitre.oval:ste:2386"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2551" version="1" check="at least one" comment="/usr/bin/xemacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1453"/>
      <state state_ref="oval:org.mitre.oval:ste:2385"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2550" version="1" check="at least one" comment="/usr/bin/xemacs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1453"/>
      <state state_ref="oval:org.mitre.oval:ste:2384"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2559" version="1" check="at least one" comment="samba version is less than 2.2.7a-8.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1458"/>
      <state state_ref="oval:org.mitre.oval:ste:2393"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2558" version="1" check="at least one" comment="smbd is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1457"/>
      <state state_ref="oval:org.mitre.oval:ste:2392"/>
    </inetlisteningservers_test>
    <patch_test id="oval:org.mitre.oval:tst:3005" version="1" check="at least one" comment="Patch 111596-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1720"/>
      <state state_ref="oval:org.mitre.oval:ste:2815"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2562" version="1" check="all" comment="Patch 108376-25 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1460"/>
      <state state_ref="oval:org.mitre.oval:ste:2395"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2561" version="1" check="all" comment="Patch 108652-30 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:876"/>
      <state state_ref="oval:org.mitre.oval:ste:2394"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:2560" version="1" check="all" comment="X Window System platform software (SUNWxwplt) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1459"/>
    </package_test>
    <file_test id="oval:org.mitre.oval:tst:2564" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 2000.80.747.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2397"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2563" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2396"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2566" version="1" check="at least one" comment="samba version is less than 2.2.7a-7.9.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1462"/>
      <state state_ref="oval:org.mitre.oval:ste:2399"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2565" version="1" check="at least one" comment="smbd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1461"/>
      <state state_ref="oval:org.mitre.oval:ste:2398"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3007" version="1" check="at least one" comment="ethereal version is less than 0.9.11-0.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1722"/>
      <state state_ref="oval:org.mitre.oval:ste:2816"/>
    </rpminfo_test>
    <file_test check="all" comment="The version of Query.dll is less than 5.2.3790.552." id="oval:org.mitre.oval:tst:21" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:104"/>
      <state state_ref="oval:org.mitre.oval:ste:152"/>
    </file_test>
    <file_test check="all" comment="The version of Query.dll is less than 5.2.3790.2734." id="oval:org.mitre.oval:tst:20" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:104"/>
      <state state_ref="oval:org.mitre.oval:ste:51"/>
    </file_test>
    <file_test check="all" comment="The version of Query.dll is less than 5.1.2600.2935." id="oval:org.mitre.oval:tst:19" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:104"/>
      <state state_ref="oval:org.mitre.oval:ste:22"/>
    </file_test>
    <file_test check="all" comment="The version of Query.dll is less than 5.1.2600.1860." id="oval:org.mitre.oval:tst:153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:104"/>
      <state state_ref="oval:org.mitre.oval:ste:62"/>
    </file_test>
    <file_test check="all" comment="The version of Query.dll is less than 5.0.2195.7100." id="oval:org.mitre.oval:tst:133" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:104"/>
      <state state_ref="oval:org.mitre.oval:ste:20"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:275" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2750.166" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:273"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:276" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 4.0.1381.33578" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:274"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2572" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.118" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2405"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2571" version="1" check="at least one" comment="the patch q832894 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1463"/>
      <state state_ref="oval:org.mitre.oval:ste:2404"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2575" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 3.70.11.46" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2408"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2574" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 3.70.11.46" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2407"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2573" version="1" check="at least one" comment="the patch q832483 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1464"/>
      <state state_ref="oval:org.mitre.oval:ste:2406"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2578" version="1" check="at least one" comment="postfix version is less than 1.1.12-1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1466"/>
      <state state_ref="oval:org.mitre.oval:ste:2411"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2577" version="1" check="at least one" comment="smtpd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1465"/>
      <state state_ref="oval:org.mitre.oval:ste:2410"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3011" version="1" check="at least one" comment="eog version is less than 2.2.0-2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1724"/>
      <state state_ref="oval:org.mitre.oval:ste:2820"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:3010" version="1" check="at least one" comment="eog is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1723"/>
      <state state_ref="oval:org.mitre.oval:ste:2819"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3009" version="1" check="at least one" comment="eog is group-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1723"/>
      <state state_ref="oval:org.mitre.oval:ste:2818"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3008" version="1" check="at least one" comment="eog is owner-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1723"/>
      <state state_ref="oval:org.mitre.oval:ste:2817"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:280" version="1" check="all" comment="Separable help for CDE (SUNWdthep) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:258"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:279" version="1" check="all" comment="Patch 107178-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:257"/>
      <state state_ref="oval:org.mitre.oval:ste:277"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:278" version="1" check="all" comment="Patch 108949-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:256"/>
      <state state_ref="oval:org.mitre.oval:ste:276"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:277" version="1" check="all" comment="Patch 116308-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:255"/>
      <state state_ref="oval:org.mitre.oval:ste:275"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3415" version="1" check="at least one" comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2556"/>
      <state state_ref="oval:org.mitre.oval:ste:3929"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:2579" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2412"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2580" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2737.800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2413"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2581" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4937.800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2414"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2582" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3813.800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2415"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:282" version="1" check="at least one" comment="the version of nddenb32.dll is less than 5.1.2600.149" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:260"/>
      <state state_ref="oval:org.mitre.oval:ste:279"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:281" version="1" check="at least one" comment="the version of netdde.exe is less than 5.1.2600.158" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:259"/>
      <state state_ref="oval:org.mitre.oval:ste:278"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:284" version="1" check="at least one" comment="the version of nntpsvc.dll is less than 5.5.1877.79" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:252"/>
      <state state_ref="oval:org.mitre.oval:ste:281"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:283" version="1" check="at least one" comment="Patch WindowsNT4OptionPack-KB883935-x86-enu.EXE" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:251"/>
      <state state_ref="oval:org.mitre.oval:ste:280"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2996" version="1" check="at least one" comment="RAS Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1714"/>
      <state state_ref="oval:org.mitre.oval:ste:2807"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3012" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3502.4856" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2821"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2587" version="1" check="at least one" comment="pine version is less than 4.44-19.90.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1468"/>
      <state state_ref="oval:org.mitre.oval:ste:2420"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2586" version="1" check="at least one" comment="/usr/bin/pine is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1467"/>
      <state state_ref="oval:org.mitre.oval:ste:2419"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2585" version="1" check="at least one" comment="/usr/bin/pine is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1467"/>
      <state state_ref="oval:org.mitre.oval:ste:2418"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2584" version="1" check="at least one" comment="/usr/bin/pine is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1467"/>
      <state state_ref="oval:org.mitre.oval:ste:2417"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:285" version="1" check="at least one" comment="the version of mqrt.dll is less than 5.0.0.799" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:261"/>
      <state state_ref="oval:org.mitre.oval:ste:282"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:292" version="1" check="all" comment="Is the .NET Framework 1.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:267"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:291" version="1" check="all" comment="Is the KB886905 patch installed for .NET Framework v1.0 sp 2?" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:266"/>
      <state state_ref="oval:org.mitre.oval:ste:288"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:290" version="1" check="at least one" comment="the version of System.web.dll is less than 1.0.3705.556" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:263"/>
      <state state_ref="oval:org.mitre.oval:ste:287"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:289" version="1" check="all" comment="Is Service Pack 2 for .NET Framework 1.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:265"/>
      <state state_ref="oval:org.mitre.oval:ste:286"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:288" version="1" check="all" comment="Is Service Pack 3 for .NET Framework 1.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:264"/>
      <state state_ref="oval:org.mitre.oval:ste:285"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:287" version="1" check="at least one" comment="the version of System.web.dll is less than 1.0.3705.6021" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:263"/>
      <state state_ref="oval:org.mitre.oval:ste:284"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:286" version="1" check="all" comment="Is the KB886906 patch installed for .NET Framework v1.0 sp 3?" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:262"/>
      <state state_ref="oval:org.mitre.oval:ste:283"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:293" version="1" check="all" comment="The SynAttackProtect parameter is set to 2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:268"/>
      <state state_ref="oval:org.mitre.oval:ste:289"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3964" version="1" check="at least one" comment="the version of umpnpmgr.dll is less than 5.1.2600.2710" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2048"/>
      <state state_ref="oval:org.mitre.oval:ste:3477"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:52" version="1" check="at least one" comment="The version of shdocvw.dll is less than 6.0.3790.588" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1659"/>
      <state state_ref="oval:org.mitre.oval:ste:175"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:48" version="1" check="at least one" comment="The version of shdocvw.dll is less than 6.0.2900.2987" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1659"/>
      <state state_ref="oval:org.mitre.oval:ste:196"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:47" version="1" check="at least one" comment="The version of shdocvw.dll is less than 6.0.3790.2783" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1659"/>
      <state state_ref="oval:org.mitre.oval:ste:38"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:43" version="1" check="at least one" comment="The version of shdocvw.dll is less than 6.0.2800.1892" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1659"/>
      <state state_ref="oval:org.mitre.oval:ste:77"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:294" version="1" check="at least one" comment="MSN Messenger 6.2.0208 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:269"/>
      <state state_ref="oval:org.mitre.oval:ste:290"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2520" version="1" check="at least one" comment="MSN Messenger 6.2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1436"/>
      <state state_ref="oval:org.mitre.oval:ste:2360"/>
    </registry_test>
    <file_test check="all" comment="The version of netapi.dll is less than 5.2.3790.559." id="oval:org.mitre.oval:tst:176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:160"/>
      <state state_ref="oval:org.mitre.oval:ste:53"/>
    </file_test>
    <file_test check="all" comment="The version of netapi.dll is less than 5.1.2600.7105." id="oval:org.mitre.oval:tst:147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:160"/>
      <state state_ref="oval:org.mitre.oval:ste:15"/>
    </file_test>
    <file_test check="all" comment="The version of netapi.dll is less than 5.0.2195.7105." id="oval:org.mitre.oval:tst:13" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:160"/>
      <state state_ref="oval:org.mitre.oval:ste:125"/>
    </file_test>
    <file_test check="all" comment="The version of netapi.dll is less than 5.2.3790.2747." id="oval:org.mitre.oval:tst:126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:160"/>
      <state state_ref="oval:org.mitre.oval:ste:191"/>
    </file_test>
    <file_test check="all" comment="The version of netapi.dll is less than 5.1.2600.2952." id="oval:org.mitre.oval:tst:101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:160"/>
      <state state_ref="oval:org.mitre.oval:ste:64"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2589" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3526.800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2422"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3014" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2823"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2590" version="1" check="at least one" comment="MDAC 2.7 (RTM) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2423"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:297" version="1" check="at least one" comment="Microsoft Proxy Server 2.0 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:272"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:296" version="1" check="at least one" comment="the version of w3proxy.dll is less than 2.0.390.16" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:271"/>
      <state state_ref="oval:org.mitre.oval:ste:292"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:295" version="1" check="at least one" comment="the patch KB888258 for Proxy Server 2.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:270"/>
      <state state_ref="oval:org.mitre.oval:ste:291"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2592" version="1" check="at least one" comment="php version is less than 4.2.2-17.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1471"/>
      <state state_ref="oval:org.mitre.oval:ste:2425"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2594" version="1" check="at least one" comment="the version of sqlisapi.dll is less than 2000.80.309.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1472"/>
      <state state_ref="oval:org.mitre.oval:ste:2427"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2593" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.760.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2426"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:300" version="1" check="at least one" comment="Patch 108993-38 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:275"/>
      <state state_ref="oval:org.mitre.oval:ste:294"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:299" version="1" check="at least one" comment="Patch 112960-17 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:274"/>
      <state state_ref="oval:org.mitre.oval:ste:293"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:298" version="1" check="at least one" comment="/etc/nsswitch.conf configured to use LDAP with RBAC" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:273"/>
    </textfilecontent_test>
    <file_test id="oval:org.mitre.oval:tst:301" version="1" check="at least one" comment="the version of wins.exe is less than 4.0.1381.7329" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:295"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2595" version="1" check="at least one" comment="File %windir%\system32\inetsrv\ssinc.dll version is less than 5.0.2195.6624" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1473"/>
      <state state_ref="oval:org.mitre.oval:ste:2428"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3017" version="1" check="at least one" comment="File admintool exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1726"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3016" version="1" check="at least one" comment="File admintool SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1726"/>
      <state state_ref="oval:org.mitre.oval:ste:2825"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:302" version="1" check="at least one" comment="the version of Llssrv.exe is less than 4.0.1381.7345" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:277"/>
      <state state_ref="oval:org.mitre.oval:ste:296"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2599" version="1" check="at least one" comment="the version of h32fltr.dll is less than 3.0.1200.291" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1477"/>
      <state state_ref="oval:org.mitre.oval:ste:2432"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2598" version="1" check="at least one" comment="the patch q816458 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1476"/>
      <state state_ref="oval:org.mitre.oval:ste:2431"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2597" version="1" check="at least one" comment="H.323 filter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1475"/>
      <state state_ref="oval:org.mitre.oval:ste:2430"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2596" version="1" check="at least one" comment="Microsoft Firewall Service is not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1474"/>
      <state state_ref="oval:org.mitre.oval:ste:2429"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:303" version="1" check="at least one" comment="the version of httpext.dll is less than 6.0.3790.212" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:278"/>
      <state state_ref="oval:org.mitre.oval:ste:297"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:304" version="1" check="at least one" comment="the version of gdi32.dll is less than 4.0.1381.33566" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:279"/>
      <state state_ref="oval:org.mitre.oval:ste:298"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:305" version="1" check="all" comment="the version of wdhtmled.ocx is less than 6.1.0.9231" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:280"/>
      <state state_ref="oval:org.mitre.oval:ste:299"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2422" version="1" check="at least one" comment="the version of mswrd6.wpc is less than 10.0.803.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1379"/>
      <state state_ref="oval:org.mitre.oval:ste:2269"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:307" version="1" check="at least one" comment="the version of hypertrm.dll is less than 5.0.2195.7000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:283"/>
      <state state_ref="oval:org.mitre.oval:ste:300"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:306" version="1" check="at least one" comment="the patch Windows2000-KB873339-x86-ENU.EXE is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:282"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3723" version="1" check="at least one" comment="the version of umpnpmgr.dll is less than 5.0.2195.7057" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2048"/>
      <state state_ref="oval:org.mitre.oval:ste:3872"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3138" version="1" check="at least one" comment="Patch 108827-30 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1785"/>
      <state state_ref="oval:org.mitre.oval:ste:2937"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3137" version="1" check="at least one" comment="Patch 108901-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1784"/>
      <state state_ref="oval:org.mitre.oval:ste:2936"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:310" version="1" check="all" comment="Patch 108451-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:286"/>
      <state state_ref="oval:org.mitre.oval:ste:303"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:309" version="1" check="all" comment="Patch 113319-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:285"/>
      <state state_ref="oval:org.mitre.oval:ste:302"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:308" version="1" check="all" comment="Patch 112233-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:284"/>
      <state state_ref="oval:org.mitre.oval:ste:301"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:311" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.241" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:304"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:313" version="1" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.7032" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:305"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:312" version="1" check="at least one" comment="the patch  KB893086 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:287"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2606" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3510.1100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2435"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2607" version="1" check="at least one" comment="perl-CGI version is less than 2.81-88.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1482"/>
      <state state_ref="oval:org.mitre.oval:ste:2436"/>
    </rpminfo_test>
    <patch_test id="oval:org.mitre.oval:tst:3018" version="1" check="at least one" comment="Patch 111826-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1727"/>
      <state state_ref="oval:org.mitre.oval:ste:2826"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2608" version="1" check="at least one" comment="pam_smb version is less than 1.1.6-9.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1483"/>
      <state state_ref="oval:org.mitre.oval:ste:2437"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2612" version="1" check="all" comment="the version of srv.sys is less than 5.0.2195.7044" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:2441"/>
    </file_test>
    <process_test id="oval:org.mitre.oval:tst:314" version="1" check="at least one" comment="Kerberos Key Distribution Center (krb5kdc) running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:288"/>
    </process_test>
    <patch_test id="oval:org.mitre.oval:tst:3505" version="1" check="at least one" comment="Patch 118822-27 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2218"/>
      <state state_ref="oval:org.mitre.oval:ste:2997"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3302" version="1" check="at least one" comment="Patch 118844-28 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1890"/>
      <state state_ref="oval:org.mitre.oval:ste:3089"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2613" version="1" check="at least one" comment="the version of hh.exe is less than 5.2.3790.309" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:859"/>
      <state state_ref="oval:org.mitre.oval:ste:2442"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2618" version="1" check="at least one" comment="openssl version is less than 0.9.7a-5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1492"/>
      <state state_ref="oval:org.mitre.oval:ste:2447"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2617" version="1" check="at least one" comment="openssl-devel version is less than 0.9.7a-5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1491"/>
      <state state_ref="oval:org.mitre.oval:ste:2446"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2616" version="1" check="at least one" comment="openssl-perl version is less than 0.9.7a-5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1490"/>
      <state state_ref="oval:org.mitre.oval:ste:2445"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2615" version="1" check="at least one" comment="openssl096 version is less than 0.9.6-17" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1489"/>
      <state state_ref="oval:org.mitre.oval:ste:2444"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2614" version="1" check="at least one" comment="openssl096b version is less than 0.9.6b-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1488"/>
      <state state_ref="oval:org.mitre.oval:ste:2443"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:316" version="1" check="at least one" comment="the version of nddenb32.dll is less than 5.2.3790.173" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:260"/>
      <state state_ref="oval:org.mitre.oval:ste:307"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:315" version="1" check="at least one" comment="the version of netdde.exe is less than 5.2.3790.184" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:259"/>
      <state state_ref="oval:org.mitre.oval:ste:306"/>
    </file_test>
    <file_test check="all" comment="The version of Rmcast.sys is less than 5.1.2600.1873." id="oval:org.mitre.oval:tst:188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:41"/>
      <state state_ref="oval:org.mitre.oval:ste:71"/>
    </file_test>
    <file_test check="all" comment="The version of Rmcast.sys is less than 5.1.2600.2951." id="oval:org.mitre.oval:tst:172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:41"/>
      <state state_ref="oval:org.mitre.oval:ste:19"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:319" version="1" check="at least one" comment="Patch 106541-25 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:291"/>
      <state state_ref="oval:org.mitre.oval:ste:310"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:318" version="1" check="at least one" comment="Patch 108528-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:290"/>
      <state state_ref="oval:org.mitre.oval:ste:309"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:317" version="1" check="at least one" comment="Patch 112233-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:289"/>
      <state state_ref="oval:org.mitre.oval:ste:308"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2621" version="1" check="at least one" comment="the version of sp3res.dll is less than 5.0.2195.6713" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1494"/>
      <state state_ref="oval:org.mitre.oval:ste:2450"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2620" version="1" check="at least one" comment="the version of umandlg.dll is less than 1.0.0.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:870"/>
      <state state_ref="oval:org.mitre.oval:ste:2449"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2619" version="1" check="at least one" comment="Patch KB822679 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1493"/>
      <state state_ref="oval:org.mitre.oval:ste:2448"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:320" version="1" check="at least one" comment="the version of hypertrm.dll is less than 4.0.1381.842" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:283"/>
      <state state_ref="oval:org.mitre.oval:ste:311"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:321" version="1" check="at least one" comment="the version of grpconv.exe (syswow64) is less than 5.2.3790.205" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:292"/>
      <state state_ref="oval:org.mitre.oval:ste:312"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2627" version="1" check="at least one" comment="openssh-server version is less than 3.5p1-11" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1498"/>
      <state state_ref="oval:org.mitre.oval:ste:2454"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2629" version="1" check="at least one" comment="openssh-server version is less than 3.5p1-6.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1500"/>
      <state state_ref="oval:org.mitre.oval:ste:2456"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2628" version="1" check="at least one" comment="sshd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1499"/>
      <state state_ref="oval:org.mitre.oval:ste:2455"/>
    </inetlisteningservers_test>
    <patch_test id="oval:org.mitre.oval:tst:325" version="1" check="all" comment="Patch 112536-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:296"/>
      <state state_ref="oval:org.mitre.oval:ste:316"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:324" version="1" check="all" comment="Patch 110057-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:295"/>
      <state state_ref="oval:org.mitre.oval:ste:315"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:323" version="1" check="all" comment="Patch 110060-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:294"/>
      <state state_ref="oval:org.mitre.oval:ste:314"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:322" version="1" check="all" comment="Patch 116462-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:293"/>
      <state state_ref="oval:org.mitre.oval:ste:313"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2631" version="1" check="at least one" comment="nfs-utils version is less than 1.0.1-3.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1502"/>
      <state state_ref="oval:org.mitre.oval:ste:2458"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2630" version="1" check="at least one" comment="rpc.mountd listens on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1501"/>
      <state state_ref="oval:org.mitre.oval:ste:2457"/>
    </inetlisteningservers_test>
    <file_test check="all" comment="The version of inetcomm.dll is less than 6.0.2900.2962." id="oval:org.mitre.oval:tst:55" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:12"/>
    </file_test>
    <file_test check="all" comment="The version of inetcomm.dll is less than 6.0.3790.2757." id="oval:org.mitre.oval:tst:11" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:13"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2632" version="1" check="at least one" comment="the version of mscms.dll is less than 5.1.2600.1710" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:745"/>
      <state state_ref="oval:org.mitre.oval:ste:2459"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3023" version="1" check="at least one" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:496"/>
      <state state_ref="oval:org.mitre.oval:ste:2831"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3022" version="1" check="at least one" comment="Patch Q269862 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1730"/>
      <state state_ref="oval:org.mitre.oval:ste:2830"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:326" version="1" check="at least one" comment="the patch WindowsServer2003-KB883935-x86-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:297"/>
      <state state_ref="oval:org.mitre.oval:ste:317"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:329" version="1" check="at least one" comment="the version of mqrt.dll is less than 5.1.0.1044" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:261"/>
      <state state_ref="oval:org.mitre.oval:ste:319"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:328" version="1" check="at least one" comment="the patch KB892944 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:299"/>
      <state state_ref="oval:org.mitre.oval:ste:318"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:327" version="1" check="at least one" comment="Message Queuing Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:298"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:330" version="1" check="at least one" comment="Patch 107115-12 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:300"/>
      <state state_ref="oval:org.mitre.oval:ste:320"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3962" version="1" check="at least one" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.005 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1871"/>
      <state state_ref="oval:org.mitre.oval:ste:3077"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:331" version="1" check="at least one" comment="Patch 107893-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:301"/>
      <state state_ref="oval:org.mitre.oval:ste:321"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2623" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.2525" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:2452"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2634" version="1" check="at least one" comment="mysql-server version is less than 3.23.56-1.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1504"/>
      <state state_ref="oval:org.mitre.oval:ste:2461"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2633" version="1" check="at least one" comment="mysqld is listening to the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1503"/>
      <state state_ref="oval:org.mitre.oval:ste:2460"/>
    </inetlisteningservers_test>
    <file_test check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.7084" id="oval:org.mitre.oval:tst:9" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1709"/>
      <state state_ref="oval:org.mitre.oval:ste:185"/>
    </file_test>
    <file_test check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.7084" id="oval:org.mitre.oval:tst:78" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1709"/>
      <state state_ref="oval:org.mitre.oval:ste:137"/>
    </file_test>
    <file_test check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.7084" id="oval:org.mitre.oval:tst:157" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1709"/>
      <state state_ref="oval:org.mitre.oval:ste:139"/>
    </file_test>
    <file_test check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.7084" id="oval:org.mitre.oval:tst:144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1709"/>
      <state state_ref="oval:org.mitre.oval:ste:21"/>
    </file_test>
    <file_test check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.7084" id="oval:org.mitre.oval:tst:108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1709"/>
      <state state_ref="oval:org.mitre.oval:ste:180"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:332" version="1" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.6970" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:322"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2638" version="1" check="at least one" comment="mutt version is less than 1.4.1-1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1506"/>
      <state state_ref="oval:org.mitre.oval:ste:2465"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2637" version="1" check="at least one" comment="/usr/bin/mutt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1505"/>
      <state state_ref="oval:org.mitre.oval:ste:2464"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2636" version="1" check="at least one" comment="/usr/bin/mutt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1505"/>
      <state state_ref="oval:org.mitre.oval:ste:2463"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2635" version="1" check="at least one" comment="/usr/bin/mutt is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1505"/>
      <state state_ref="oval:org.mitre.oval:ste:2462"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2946" version="1" check="at least one" comment="Patch 110896-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1686"/>
      <state state_ref="oval:org.mitre.oval:ste:2761"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:333" version="1" check="at least one" comment="the version of vdmdbg.dll is less than 5.0.2195.6946" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:302"/>
      <state state_ref="oval:org.mitre.oval:ste:323"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:35" version="1" check="at least one" comment="the version of excel.exe is less than 9.0.0.8950" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:170"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:27" version="1" check="at least one" comment="the version of excel.exe is less than 11.0.8104.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:659"/>
      <state state_ref="oval:org.mitre.oval:ste:132"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:26" version="1" check="at least one" comment="the version of excel.exe is less than 11.0.8105.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:25"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:173" version="1" check="at least one" comment="the version of excel.exe is less than 10.0.6816.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:24"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:334" version="1" check="at least one" comment="Microsoft Visual Studio .NET 2002 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:303"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2639" version="1" check="at least one" comment="lv version is less than 4.49.4-9.9.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1507"/>
      <state state_ref="oval:org.mitre.oval:ste:2466"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2640" version="1" check="at least one" comment="the version of msohev.dll less than 10.0.2609.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1508"/>
      <state state_ref="oval:org.mitre.oval:ste:2467"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:335" version="1" check="at least one" comment="the version of Dhcpssvc.dll is less than 4.0.1381.33587" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:304"/>
      <state state_ref="oval:org.mitre.oval:ste:324"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:41" version="1" check="all" comment="the version of srv.sys is less than 5.2.3790.588" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:102"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:40" version="1" check="all" comment="the version of srv.sys is less than 5.2.3790.2783" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:52"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:39" version="1" check="all" comment="the version of srv.sys is less than 5.1.2600.1885" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:189"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:37" version="1" check="all" comment="the version of srv.sys is less than 5.0.2195.7106" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:31"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:111" version="1" check="all" comment="the version of srv.sys is less than 5.1.2600.2974" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:32"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:336" version="1" check="at least one" comment="the 64-bit WOW version of zipfldr.dll is less than 6.0.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:250"/>
      <state state_ref="oval:org.mitre.oval:ste:325"/>
    </file_test>
    <registry_test check="at least one" comment="Publisher 2000 is installed" id="oval:org.mitre.oval:tst:22" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:109"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:338" version="1" check="at least one" comment="the version of msphlpr.dll is less than 3.0.1200.408" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:306"/>
      <state state_ref="oval:org.mitre.oval:ste:327"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:337" version="1" check="at least one" comment="the patch KB888258 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:305"/>
      <state state_ref="oval:org.mitre.oval:ste:326"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:339" version="1" check="at least one" comment="the version of grpconv.exe (system32) is less than 5.2.3790.205" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:307"/>
      <state state_ref="oval:org.mitre.oval:ste:328"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2644" version="1" check="at least one" comment="the version of tlntsvr.exe is less than 5.0.33668.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1513"/>
      <state state_ref="oval:org.mitre.oval:ste:2470"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2643" version="1" check="at least one" comment="Patch Q307298 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1512"/>
      <state state_ref="oval:org.mitre.oval:ste:2469"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2642" version="1" check="at least one" comment="the telnet service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1511"/>
      <state state_ref="oval:org.mitre.oval:ste:2468"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2647" version="1" check="at least one" comment="lprng version is less than 3.8.19-3.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1516"/>
      <state state_ref="oval:org.mitre.oval:ste:2473"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2646" version="1" check="at least one" comment="psbanner is world-executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1515"/>
      <state state_ref="oval:org.mitre.oval:ste:2472"/>
    </file_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2645" version="1" check="at least one" comment="lpd listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1514"/>
      <state state_ref="oval:org.mitre.oval:ste:2471"/>
    </inetlisteningservers_test>
    <file_test id="oval:org.mitre.oval:tst:341" version="1" check="at least one" comment="the version of vgx.dll is less than 6.0.2800.1411" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:308"/>
      <state state_ref="oval:org.mitre.oval:ste:329"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:4132" version="1" check="at least one" comment="Patch PHNE_33412 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2341"/>
      <state state_ref="oval:org.mitre.oval:ste:3549"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3193" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2530"/>
      <state state_ref="oval:org.mitre.oval:ste:3743"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:3140" version="1" check="at least one" comment="File rpc.cmsd exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1781"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3139" version="1" check="at least one" comment="File dmispd exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1786"/>
    </file_test>
    <inetd_test id="oval:org.mitre.oval:tst:3136" version="1" check="at least one" comment="inetd.conf contains rpc.cmsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1783"/>
      <state state_ref="oval:org.mitre.oval:ste:2935"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:3134" version="1" check="at least one" comment="File rpc.cmsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1781"/>
      <state state_ref="oval:org.mitre.oval:ste:2933"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3133" version="1" check="at least one" comment="File rpc.cmsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1781"/>
      <state state_ref="oval:org.mitre.oval:ste:2932"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3132" version="1" check="at least one" comment="File rpc.cmsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1781"/>
      <state state_ref="oval:org.mitre.oval:ste:2931"/>
    </file_test>
    <process_test id="oval:org.mitre.oval:tst:3131" version="1" check="at least one" comment="dmispd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1780"/>
    </process_test>
    <patch_test id="oval:org.mitre.oval:tst:3026" version="1" check="at least one" comment="Patch 106942-22 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:484"/>
      <state state_ref="oval:org.mitre.oval:ste:2834"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3025" version="1" check="at least one" comment="Patch 108541-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1732"/>
      <state state_ref="oval:org.mitre.oval:ste:2833"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:345" version="1" check="all" comment="Patch 106938-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:313"/>
      <state state_ref="oval:org.mitre.oval:ste:332"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:344" version="1" check="all" comment="Patch 109326-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:312"/>
      <state state_ref="oval:org.mitre.oval:ste:331"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:343" version="1" check="all" comment="Patch 112970-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:311"/>
      <state state_ref="oval:org.mitre.oval:ste:330"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:342" version="1" check="all" comment="/etc/nsswitch.conf configured to resolve hosts through DNS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:310"/>
    </textfilecontent_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2656" version="1" check="at least one" comment="kdelibs version is less than 3.1-12" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1521"/>
      <state state_ref="oval:org.mitre.oval:ste:2481"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2655" version="1" check="at least one" comment="/usr/bin/konqueror is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1520"/>
      <state state_ref="oval:org.mitre.oval:ste:2480"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2654" version="1" check="at least one" comment="/usr/bin/konqueror is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1520"/>
      <state state_ref="oval:org.mitre.oval:ste:2479"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2653" version="1" check="at least one" comment="/usr/bin/konqueror is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1520"/>
      <state state_ref="oval:org.mitre.oval:ste:2478"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3609" version="1" check="at least one" comment="Patch PHNE_34077 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2051"/>
      <state state_ref="oval:org.mitre.oval:ste:3005"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3519" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2424"/>
      <state state_ref="oval:org.mitre.oval:ste:3434"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:3032" version="1" check="at least one" comment="File rpc.rwalld exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1733"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3031" version="1" check="at least one" comment="Patch 112899-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1735"/>
      <state state_ref="oval:org.mitre.oval:ste:2839"/>
    </patch_test>
    <inetd_test id="oval:org.mitre.oval:tst:3030" version="1" check="at least one" comment="inetd.conf contains rpc.rwalld" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1734"/>
      <state state_ref="oval:org.mitre.oval:ste:2838"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:3029" version="1" check="at least one" comment="File rpc.rwalld executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1733"/>
      <state state_ref="oval:org.mitre.oval:ste:2837"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3028" version="1" check="at least one" comment="File rpc.rwalld executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1733"/>
      <state state_ref="oval:org.mitre.oval:ste:2836"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3027" version="1" check="at least one" comment="File rpc.rwalld executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1733"/>
      <state state_ref="oval:org.mitre.oval:ste:2835"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:352" version="1" check="all" comment="Solaris Print - Client - Root (SUNWpcr) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:319"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:351" version="1" check="all" comment="Solaris Print - Client - Usr (SUNWpcu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:318"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:350" version="1" check="all" comment="Solaris Print - LP Server - Root (SUNWpsr) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:317"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:349" version="1" check="all" comment="Solaris Print - LP Server - Usr (SUNWpsu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:316"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:348" version="1" check="all" comment="Patch 107115-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:300"/>
      <state state_ref="oval:org.mitre.oval:ste:335"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:347" version="1" check="all" comment="Patch 109320-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:315"/>
      <state state_ref="oval:org.mitre.oval:ste:334"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:346" version="1" check="all" comment="Patch 113329-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:314"/>
      <state state_ref="oval:org.mitre.oval:ste:333"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2658" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.280" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:2482"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2662" version="1" check="at least one" comment="the version of w3proxy.exe is less than 3.0.1200.257" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1526"/>
      <state state_ref="oval:org.mitre.oval:ste:2486"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2661" version="1" check="at least one" comment="the version of wpsrv.exe is less than 3.0.1200.257" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1524"/>
      <state state_ref="oval:org.mitre.oval:ste:2485"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2660" version="1" check="at least one" comment="Patch isahf257 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1523"/>
      <state state_ref="oval:org.mitre.oval:ste:2484"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2659" version="1" check="at least one" comment="Microsoft Firewall Service Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1474"/>
      <state state_ref="oval:org.mitre.oval:ste:2483"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:358" version="1" check="all" comment="Patch 108574-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:325"/>
      <state state_ref="oval:org.mitre.oval:ste:341"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:357" version="1" check="all" comment="Patch 108162-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:324"/>
      <state state_ref="oval:org.mitre.oval:ste:340"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:356" version="1" check="all" comment="Patch 108416-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:323"/>
      <state state_ref="oval:org.mitre.oval:ste:339"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:355" version="1" check="all" comment="Patch 110943-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:322"/>
      <state state_ref="oval:org.mitre.oval:ste:338"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:354" version="1" check="all" comment="Patch 110898-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:321"/>
      <state state_ref="oval:org.mitre.oval:ste:337"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:353" version="1" check="all" comment="Patch 109324-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:320"/>
      <state state_ref="oval:org.mitre.oval:ste:336"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:359" version="1" check="at least one" comment="the version of mrxsmb.sys is less than 5.0.2195.7023" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:342"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:362" version="1" check="at least one" comment="Exchange Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:330"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:361" version="1" check="at least one" comment="the version of xlsasink.dll is less than 6.5.6981.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:328"/>
      <state state_ref="oval:org.mitre.oval:ste:343"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:360" version="1" check="at least one" comment="the patch KB894549 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:327"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:365" version="1" check="at least one" comment="Patch 109613-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:333"/>
      <state state_ref="oval:org.mitre.oval:ste:345"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:364" version="1" check="at least one" comment="Patch 112810-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:332"/>
      <state state_ref="oval:org.mitre.oval:ste:344"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:363" version="1" check="at least one" comment="CDE Desktop Applications (SUNWdtdst) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:331"/>
    </package_test>
    <file_test id="oval:org.mitre.oval:tst:367" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33591" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:347"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:368" version="1" check="at least one" comment="the version of sxs.dll is less than 5.1.2600.1363" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:336"/>
      <state state_ref="oval:org.mitre.oval:ste:348"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:38" version="1" check="at least one" comment="Word Viewer is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1517"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:57" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8951" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:72"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:28" version="1" check="at least one" comment="the version of wordview.exe is less than 11.0.8104.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1517"/>
      <state state_ref="oval:org.mitre.oval:ste:68"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:151" version="1" check="at least one" comment="the version of winword.exe is less than 11.0.8106.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:43"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:107" version="1" check="at least one" comment="the version of winword.exe is less than 10.0.6818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:27"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:370" version="1" check="at least one" comment="the version of hypertrm.dll is less than 4.0.1381.7323" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:283"/>
      <state state_ref="oval:org.mitre.oval:ste:349"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:369" version="1" check="at least one" comment="the patch NT Server kb873339 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:337"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:3898" version="1" check="at least one" comment="Patch 112238-12 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1830"/>
      <state state_ref="oval:org.mitre.oval:ste:2974"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3694" version="1" check="at least one" comment="Pkg SUNWcryr (Supplemental Encryption) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2551"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:3640" version="1" check="at least one" comment="Patch 112390-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2709"/>
      <state state_ref="oval:org.mitre.oval:ste:3522"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3624" version="1" check="at least one" comment="Patch 115168-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1845"/>
      <state state_ref="oval:org.mitre.oval:ste:3074"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3576" version="1" check="at least one" comment="Solaris 7 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3679"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:3567" version="1" check="at least one" comment="Patch 112237-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2466"/>
      <state state_ref="oval:org.mitre.oval:ste:3846"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3561" version="1" check="at least one" comment="Patch 120469-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2128"/>
      <state state_ref="oval:org.mitre.oval:ste:3272"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3497" version="1" check="at least one" comment="Patch 112240-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2599"/>
      <state state_ref="oval:org.mitre.oval:ste:2988"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3424" version="1" check="at least one" comment="Patch 112537-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2196"/>
      <state state_ref="oval:org.mitre.oval:ste:2965"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3418" version="1" check="at least one" comment="Patch 120470-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2752"/>
      <state state_ref="oval:org.mitre.oval:ste:3688"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3389" version="1" check="at least one" comment="Patch 112908-20 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2309"/>
      <state state_ref="oval:org.mitre.oval:ste:3041"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3209" version="1" check="at least one" comment="Patch 112536-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1847"/>
      <state state_ref="oval:org.mitre.oval:ste:3585"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3198" version="1" check="at least one" comment="Pkg SUNWcry (Supplemental Encryption) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2361"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:372" version="1" check="all" comment="Patch 109326-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:312"/>
      <state state_ref="oval:org.mitre.oval:ste:350"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:371" version="1" check="all" comment="File /etc/named.conf exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oval-def:notes>
        <oval-def:note>The presence of /etc/named.conf indicates that system system is probably configured as a DNS server</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:338"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:373" version="1" check="at least one" comment="the version of gdi32.dll is less than 4.0.1381.7270" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:279"/>
      <state state_ref="oval:org.mitre.oval:ste:351"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2663" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2734.1600" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2487"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:374" version="1" check="at least one" comment="the 32-bit version of zipfldr.dll is less than 6.0.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:339"/>
      <state state_ref="oval:org.mitre.oval:ste:352"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:375" version="1" check="at least one" comment="Microsoft Office XP Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:334"/>
      <state state_ref="oval:org.mitre.oval:ste:353"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:379" version="1" check="all" comment="NTP daemon - Usr (SUNWntpu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:343"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:378" version="1" check="all" comment="Patch 109409-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:342"/>
      <state state_ref="oval:org.mitre.oval:ste:355"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:377" version="1" check="all" comment="Patch 109667-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:341"/>
      <state state_ref="oval:org.mitre.oval:ste:354"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:376" version="1" check="all" comment="xntpd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:340"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:381" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:357"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:380" version="1" check="at least one" comment="the version of shell32.dll (WOW64) is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:344"/>
      <state state_ref="oval:org.mitre.oval:ste:356"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:382" version="1" check="at least one" comment="Project Professional 2003 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:345"/>
      <state state_ref="oval:org.mitre.oval:ste:358"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2670" version="1" check="at least one" comment="the version of hh.exe is less than 5.2.3790.2427" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:859"/>
      <state state_ref="oval:org.mitre.oval:ste:2494"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3034" version="1" check="at least one" comment="the version of srvsvc.dll is less than 5.0.2195.4980" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:397"/>
      <state state_ref="oval:org.mitre.oval:ste:2841"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3033" version="1" check="at least one" comment="Patch Q318593 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1736"/>
      <state state_ref="oval:org.mitre.oval:ste:2840"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:383" version="1" check="at least one" comment="Patch 113146-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:215"/>
      <state state_ref="oval:org.mitre.oval:ste:359"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:384" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4945.2800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:360"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:42" version="1" check="at least one" comment="the version of System.web.dll is less than 2.0.50727.210" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:4"/>
      <state state_ref="oval:org.mitre.oval:ste:33"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3639" version="1" check="at least one" comment="the version of rdpwd.sys is less than 5.1.2600.2695" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2219"/>
      <state state_ref="oval:org.mitre.oval:ste:3045"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2338" version="1" check="all" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1498" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2189"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2337" version="1" check="all" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1499" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2188"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2336" version="1" check="at least one" comment="the patch kb890923 is installed (XP Win2K Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1340"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2676" version="1" check="at least one" comment="the version of hhctrl.ocx is less than 5.2.3669.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:531"/>
      <state state_ref="oval:org.mitre.oval:ste:2500"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2675" version="1" check="at least one" comment="the version of hhsetup.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1532"/>
      <state state_ref="oval:org.mitre.oval:ste:2499"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2674" version="1" check="at least one" comment="the version of itircl.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1531"/>
      <state state_ref="oval:org.mitre.oval:ste:2498"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2673" version="1" check="at least one" comment="the version of itss.dll is less than 5.2.3644.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:966"/>
      <state state_ref="oval:org.mitre.oval:ste:2497"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2672" version="1" check="at least one" comment="the patch q323255 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1530"/>
      <state state_ref="oval:org.mitre.oval:ste:2496"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2988" version="1" check="at least one" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1709"/>
      <state state_ref="oval:org.mitre.oval:ste:2801"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3039" version="1" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1631"/>
      <state state_ref="oval:org.mitre.oval:ste:2846"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2679" version="1" check="at least one" comment="the version of fp5areg.dll is less than 10.00.4205.0000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1535"/>
      <state state_ref="oval:org.mitre.oval:ste:2502"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2678" version="1" check="at least one" comment="the version of fp30reg.dll is less than 10.00.4205.0000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1534"/>
      <state state_ref="oval:org.mitre.oval:ste:2501"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2677" version="1" check="at least one" comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1533"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:388" version="1" check="at least one" comment="libpng rpm older than 1.2.2-24, Epoch 2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:349"/>
      <state state_ref="oval:org.mitre.oval:ste:364"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:387" version="1" check="at least one" comment="libpng-devel rpm older than 1.2.2-24, Epoch 2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:348"/>
      <state state_ref="oval:org.mitre.oval:ste:363"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:386" version="1" check="at least one" comment="libpng10-devel rpm older than 1.0.13-14, Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:347"/>
      <state state_ref="oval:org.mitre.oval:ste:362"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:385" version="1" check="at least one" comment="libpng10 rpm older than 1.0.13-14, Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:346"/>
      <state state_ref="oval:org.mitre.oval:ste:361"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2681" version="1" check="at least one" comment="the version of fp4areg.dll is less than 4.0.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1537"/>
      <state state_ref="oval:org.mitre.oval:ste:2504"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2680" version="1" check="at least one" comment="the version of fp30reg.dll is less than 4.00.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1536"/>
      <state state_ref="oval:org.mitre.oval:ste:2503"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:390" version="1" check="at least one" comment="Patch 108528-18 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:290"/>
      <state state_ref="oval:org.mitre.oval:ste:366"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:389" version="1" check="at least one" comment="Patch 112233-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:289"/>
      <state state_ref="oval:org.mitre.oval:ste:365"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:394" version="1" check="at least one" comment="the version of shell32.dll is less than 4.72.3841.1100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:369"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:397" version="1" check="all" comment="Patch 106950-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:354"/>
      <state state_ref="oval:org.mitre.oval:ste:372"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:396" version="1" check="all" comment="Patch 109147-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:353"/>
      <state state_ref="oval:org.mitre.oval:ste:371"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:395" version="1" check="all" comment="Patch 112963-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:352"/>
      <state state_ref="oval:org.mitre.oval:ste:370"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:4067" version="1" check="at least one" comment="Patch 120954-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2778"/>
      <state state_ref="oval:org.mitre.oval:ste:3473"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:3551" version="1" check="at least one" comment="Sun Java System Access Manager 7 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2033"/>
      <state state_ref="oval:org.mitre.oval:ste:3088"/>
    </package_test>
    <registry_test id="oval:org.mitre.oval:tst:1" version="1" check="at least one" comment="Windows NT is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:123"/>
      <state state_ref="oval:org.mitre.oval:ste:2"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:400" version="1" check="at least one" comment="the version of webvw.dll is less than 5.0.3900.7036" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:357"/>
      <state state_ref="oval:org.mitre.oval:ste:374"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:399" version="1" check="at least one" comment="the patch KB894320 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:356"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:398" version="1" check="at least one" comment="Webview is  Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:355"/>
      <state state_ref="oval:org.mitre.oval:ste:373"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:401" version="1" check="at least one" comment="the version of Llssrv.exe is less than 5.2.3790.242" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:277"/>
      <state state_ref="oval:org.mitre.oval:ste:375"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2683" version="1" check="all" comment="cpio rpm is older than 0:2.5-4.RHEL3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1539"/>
      <state state_ref="oval:org.mitre.oval:ste:2506"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2682" version="1" check="all" comment="/bin/cpio is executable by all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1538"/>
      <state state_ref="oval:org.mitre.oval:ste:2505"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:403" version="1" check="at least one" comment="MDAC 2.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:377"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:402" version="1" check="at least one" comment="the version of msadco.dll is less than 2.12.5118.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:376"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1486" version="1" check="at least one" comment="the version of ole32.dll is less than 5.2.3790.250" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:1343"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:406" version="1" check="at least one" comment="Patch 114332-08 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:361"/>
      <state state_ref="oval:org.mitre.oval:ste:379"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:405" version="1" check="at least one" comment="Patch 114332-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:361"/>
      <state state_ref="oval:org.mitre.oval:ste:378"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:404" version="1" check="at least one" comment="/etc/system has BSM enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:360"/>
    </textfilecontent_test>
    <registry_test id="oval:org.mitre.oval:tst:412" version="1" check="all" comment="Is the .NET Framework 1.1 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:365"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:411" version="1" check="all" comment="Is Service Pack 1 for .NET Framework 1.1 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:364"/>
      <state state_ref="oval:org.mitre.oval:ste:384"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:410" version="1" check="at least one" comment="the version of System.web.dll is less than 1.1.4322.2037" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:263"/>
      <state state_ref="oval:org.mitre.oval:ste:383"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:409" version="1" check="all" comment="Is the KB886903 patch installed for .NET Framework v1.1 sp 1?" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:363"/>
      <state state_ref="oval:org.mitre.oval:ste:382"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:408" version="1" check="at least one" comment="the version of System.web.dll is less than 1.1.4322.1085" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:263"/>
      <state state_ref="oval:org.mitre.oval:ste:381"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:407" version="1" check="all" comment="Is the KB886904 patch installed for .NET Framework v1.1 Gold?" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:362"/>
      <state state_ref="oval:org.mitre.oval:ste:380"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:413" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1634" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:385"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:3969" version="1" check="at least one" comment="OS-Core.ARRAY-MGMT (B.11.00) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2749"/>
      <state state_ref="oval:org.mitre.oval:ste:3311"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3707" version="1" check="at least one" comment="OS-Core.ADMN-ENG-A-MAN (B.11.00) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2181"/>
      <state state_ref="oval:org.mitre.oval:ste:3127"/>
    </swlist_test>
    <uname_test id="oval:org.mitre.oval:tst:3540" version="1" check="all" comment="HP Release B.11.10" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3695"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:3536" version="1" check="at least one" comment="Patch PHCO_23262 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2516"/>
      <state state_ref="oval:org.mitre.oval:ste:3260"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3449" version="1" check="at least one" comment="OS-Core.ARRAY-MGMT (B.11.10) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2481"/>
      <state state_ref="oval:org.mitre.oval:ste:3442"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3377" version="1" check="at least one" comment="OS-Core.ADMN-ENG-A-MAN (B.11.10) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2293"/>
      <state state_ref="oval:org.mitre.oval:ste:3683"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:414" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2600.151" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:386"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:417" version="1" check="at least one" comment="Secure Shell Server - Usr (SUNWsshdu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:368"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:416" version="1" check="at least one" comment="Patch 113273-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:367"/>
      <state state_ref="oval:org.mitre.oval:ste:387"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:415" version="1" check="at least one" comment="/etc/ssh/sshd_config has 0.0.0.0 as ListenAddress" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:366"/>
    </textfilecontent_test>
    <file_test id="oval:org.mitre.oval:tst:2684" version="1" check="all" comment="/etc/httpd/conf.d/php.conf exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1540"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:418" version="1" check="at least one" comment="the patch Q890175 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:369"/>
      <state state_ref="oval:org.mitre.oval:ste:388"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2686" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.94" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2508"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2685" version="1" check="at least one" comment="the patch q824145 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1541"/>
      <state state_ref="oval:org.mitre.oval:ste:2507"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:422" version="1" check="at least one" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:372"/>
      <state state_ref="oval:org.mitre.oval:ste:392"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:421" version="1" check="at least one" comment=" Patch WindowsXP-KB824105-x86-ENU.exe installed on XP SP1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:371"/>
      <state state_ref="oval:org.mitre.oval:ste:391"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:420" version="1" check="at least one" comment="the version of netbt.sys is less than 5.1.2600.117" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:370"/>
      <state state_ref="oval:org.mitre.oval:ste:390"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:419" version="1" check="at least one" comment="the version of netbt.sys is less than 5.1.2600.1243" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:370"/>
      <state state_ref="oval:org.mitre.oval:ste:389"/>
    </file_test>
    <file_test check="all" comment="The version of mso.dll is less than 10.0.6811.0." id="oval:org.mitre.oval:tst:17" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:467"/>
      <state state_ref="oval:org.mitre.oval:ste:34"/>
    </file_test>
    <file_test check="all" comment="The version of mso9.dll is less than 9.0.0.8948." id="oval:org.mitre.oval:tst:16" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1"/>
      <state state_ref="oval:org.mitre.oval:ste:17"/>
    </file_test>
    <file_test check="all" comment="The version of mso.dll is less than 11.0.8036.0." id="oval:org.mitre.oval:tst:110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:398"/>
      <state state_ref="oval:org.mitre.oval:ste:188"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:427" version="1" check="all" comment="the version of dhtmled.ocx is less than 6.1.0.9232" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:377"/>
      <state state_ref="oval:org.mitre.oval:ste:394"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:428" version="1" check="at least one" comment="the patch WindowsServer2003-KB885881-ia64-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:378"/>
      <state state_ref="oval:org.mitre.oval:ste:395"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3760" version="1" check="at least one" comment="the version of rdpwd.sys is less than 5.2.3790.2465" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2219"/>
      <state state_ref="oval:org.mitre.oval:ste:3006"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2657" version="1" check="at least one" comment="the patch  KB893086 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1522"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2687" version="1" check="all" comment="php RPM prior to  0:4.3.2-24.ent" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1542"/>
      <state state_ref="oval:org.mitre.oval:ste:2509"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2688" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1276" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2510"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2689" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4934.1600" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2511"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:429" version="1" check="at least one" comment="the version of mstask.dll is less than 4.71.2195.6920" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:379"/>
      <state state_ref="oval:org.mitre.oval:ste:396"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2690" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3810.1700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2512"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:433" version="1" check="all" comment="Solaris Basic IP Commands (SUNWbip) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:383"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:432" version="1" check="at least one" comment="Patch 118313-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:382"/>
      <state state_ref="oval:org.mitre.oval:ste:399"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:431" version="1" check="at least one" comment="Patch 116986-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:381"/>
      <state state_ref="oval:org.mitre.oval:ste:398"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:430" version="1" check="at least one" comment="Patch 116774-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:380"/>
      <state state_ref="oval:org.mitre.oval:ste:397"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2691" version="1" check="at least one" comment="File %windir%\system32\user32.dll version is less than 5.0.2195.6799" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:2513"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3043" version="1" check="at least one" comment="File whodo exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1742"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3042" version="1" check="at least one" comment="Patch 111600-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1741"/>
      <state state_ref="oval:org.mitre.oval:ste:2849"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3041" version="1" check="at least one" comment="File whodo SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1740"/>
      <state state_ref="oval:org.mitre.oval:ste:2848"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3040" version="1" check="at least one" comment="File whodo SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1740"/>
      <state state_ref="oval:org.mitre.oval:ste:2847"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:435" version="1" check="at least one" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.112" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:384"/>
      <state state_ref="oval:org.mitre.oval:ste:401"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:434" version="1" check="at least one" comment="File %windir%system32DriversSRV.SYS is less than 5.1.2600.1193" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:384"/>
      <state state_ref="oval:org.mitre.oval:ste:400"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:91" version="1" check="at least one" comment="The version of Comctl32.dll is less than 5.82.2800.1891" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:22"/>
      <state state_ref="oval:org.mitre.oval:ste:166"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:59" version="1" check="at least one" comment="The version of Comctl32.dll is less than 5.82.3790.583" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:22"/>
      <state state_ref="oval:org.mitre.oval:ste:73"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:58" version="1" check="at least one" comment="The version of Comctl32.dll is less than 5.82.3790.2778" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:22"/>
      <state state_ref="oval:org.mitre.oval:ste:198"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:54" version="1" check="at least one" comment="The version of Comctl32.dll is less than 5.82.2900.2982" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:22"/>
      <state state_ref="oval:org.mitre.oval:ste:41"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:135" version="1" check="at least one" comment="The version of Comctl32.dll is less than 5.81.3900.7109" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:22"/>
      <state state_ref="oval:org.mitre.oval:ste:94"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:436" version="1" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.6922" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:402"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:437" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2742.200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:403"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1353" version="1" check="at least one" comment="Outlook Express 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:566"/>
      <state state_ref="oval:org.mitre.oval:ste:1215"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2692" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8216" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2514"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2400" version="1" check="at least one" comment="the version of user32.dll is less than 4.0.1381.7342" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:2248"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2693" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3523.1700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2515"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2695" version="1" check="at least one" comment="the version of nntpsvc.dll is less than 5.0.2195.3881" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:252"/>
      <state state_ref="oval:org.mitre.oval:ste:2517"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2694" version="1" check="at least one" comment="Patch Q303984 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1543"/>
      <state state_ref="oval:org.mitre.oval:ste:2516"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1592" version="1" check="at least one" comment="Microsoft Office XP Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:334"/>
      <state state_ref="oval:org.mitre.oval:ste:1446"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:439" version="1" check="at least one" comment="Visio Professional 2003 is Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:387"/>
      <state state_ref="oval:org.mitre.oval:ste:405"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:438" version="1" check="at least one" comment="the version of gdiplus.dll is less than 6.0.3264.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:386"/>
      <state state_ref="oval:org.mitre.oval:ste:404"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:440" version="1" check="at least one" comment="Patch KB873378 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:388"/>
      <state state_ref="oval:org.mitre.oval:ste:406"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:441" version="1" check="at least one" comment="the version of wordpad.exe is less than 4.0.1381.7312" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:389"/>
      <state state_ref="oval:org.mitre.oval:ste:407"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2696" version="1" check="at least one" comment="the workstation service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1544"/>
      <state state_ref="oval:org.mitre.oval:ste:2518"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2698" version="1" check="at least one" comment="the version of mscms.dll is less than 5.1.2600.2709" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:745"/>
      <state state_ref="oval:org.mitre.oval:ste:2520"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3044" version="1" check="at least one" comment="Patch 108376-38 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1460"/>
      <state state_ref="oval:org.mitre.oval:ste:2850"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:445" version="1" check="at least one" comment="the version of netdde.exe is less than 5.1.2600.1567" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:259"/>
      <state state_ref="oval:org.mitre.oval:ste:411"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:444" version="1" check="at least one" comment="the 64-bit WOW version of netdde.exe is less than 5.1.2600.1567" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:249"/>
      <state state_ref="oval:org.mitre.oval:ste:410"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:443" version="1" check="at least one" comment="the version of nddenb32.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:260"/>
      <state state_ref="oval:org.mitre.oval:ste:409"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:442" version="1" check="at least one" comment="the 64-bit WOW version of nddenb32.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:248"/>
      <state state_ref="oval:org.mitre.oval:ste:408"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:446" version="1" check="at least one" comment="the version of user32.dll is less than 5.0.2195.7017" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:412"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2700" version="1" check="at least one" comment="the version of wmplayer.exe is less than 8.0.0.4490" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1547"/>
      <state state_ref="oval:org.mitre.oval:ste:2522"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2699" version="1" check="at least one" comment="Patch WindowsMedia8-KB817787-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1546"/>
      <state state_ref="oval:org.mitre.oval:ste:2521"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:448" version="1" check="at least one" comment="machine has followed the GDR update path and hlink.dll is less than 5.2.3790.225" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:391"/>
      <state state_ref="oval:org.mitre.oval:ste:414"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:447" version="1" check="at least one" comment="machine has followed the QFE update path and hlink.dll is less than 5.2.3790.227" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:391"/>
      <state state_ref="oval:org.mitre.oval:ste:413"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2702" version="1" check="at least one" comment="the version of kernel32.dll is less than 4.0.1381.7224" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:2524"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2701" version="1" check="at least one" comment="Patch Q823803 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1548"/>
      <state state_ref="oval:org.mitre.oval:ste:2523"/>
    </registry_test>
    <file_test check="all" comment="The version of shell32.dll is less than 6.0.2800.1873." id="oval:org.mitre.oval:tst:199" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:14"/>
    </file_test>
    <file_test check="all" comment="The version of shell32.dll is less than 6.0.2900.2951." id="oval:org.mitre.oval:tst:160" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:111"/>
    </file_test>
    <file_test check="all" comment="The version of shell32.dll is less than 6.0.3790.559." id="oval:org.mitre.oval:tst:14" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:156"/>
    </file_test>
    <file_test check="all" comment="The version of shell32.dll is less than 5.0.3900.7105." id="oval:org.mitre.oval:tst:129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:135"/>
    </file_test>
    <file_test check="all" comment="The version of shell32.dll is less than 6.0.3790.2746." id="oval:org.mitre.oval:tst:12" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:37"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2704" version="1" check="at least one" comment="the version of impprov.dll is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1551"/>
      <state state_ref="oval:org.mitre.oval:ste:2526"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:449" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6159" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:415"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:451" version="1" check="at least one" comment="the patch Windows 2003 kb873339 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:392"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:450" version="1" check="at least one" comment="the version of hypertrm.dll is less than 5.2.3790.233" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:283"/>
      <state state_ref="oval:org.mitre.oval:ste:416"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:453" version="1" check="at least one" comment="the version of netdde.exe is less than 5.0.2195.6952" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:393"/>
      <state state_ref="oval:org.mitre.oval:ste:418"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:452" version="1" check="at least one" comment="the version of nddenb32.dll is less than 5.0.2195.6922" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:393"/>
      <state state_ref="oval:org.mitre.oval:ste:417"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3559" version="1" check="at least one" comment="Patch PHSS_30302 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1862"/>
      <state state_ref="oval:org.mitre.oval:ste:3169"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3243" version="1" check="at least one" comment="Patch PHCO_30006 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2785"/>
      <state state_ref="oval:org.mitre.oval:ste:3779"/>
    </patch_test>
    <registry_test check="all" comment="The .NET Framework 2.0 is installed" id="oval:org.mitre.oval:tst:190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:156"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:3052" version="1" check="at least one" comment="Patch 110896-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1686"/>
      <state state_ref="oval:org.mitre.oval:ste:2858"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3050" version="1" check="at least one" comment="Patch 114008-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1745"/>
      <state state_ref="oval:org.mitre.oval:ste:2856"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:454" version="1" check="at least one" comment="the version of user32.dll is less than 4.0.1381.33630" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:419"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:457" version="1" check="at least one" comment="Patch KB821557 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:394"/>
      <state state_ref="oval:org.mitre.oval:ste:422"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:456" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1233" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:421"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:455" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2600.115" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:420"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2708" version="1" check="at least one" comment="the version of shtml.dll is less than 4.00.02.7523" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1555"/>
      <state state_ref="oval:org.mitre.oval:ste:2529"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2707" version="1" check="at least one" comment="the patch q810217 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1554"/>
      <state state_ref="oval:org.mitre.oval:ste:2528"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2706" version="1" check="at least one" comment="FrontPage Server Extensions 2000 are enabled (2K, XP)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1553"/>
      <state state_ref="oval:org.mitre.oval:ste:2527"/>
    </registry_test>
    <metabase_test id="oval:org.mitre.oval:tst:2705" version="1" check="at least one" comment="SmartHTML interpreter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1552"/>
    </metabase_test>
    <package_test id="oval:org.mitre.oval:tst:459" version="1" check="all" comment="CDE application basic runtime environment (SUNWdtbas/SUNWdtbax) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:396"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:458" version="1" check="at least one" comment="Patch 108219-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:395"/>
      <state state_ref="oval:org.mitre.oval:ste:423"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:461" version="1" check="at least one" comment="the version of grpconv.exe (system32) is less than 4.0.1381.7286" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:307"/>
      <state state_ref="oval:org.mitre.oval:ste:425"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:460" version="1" check="at least one" comment="the version of grpconv.exe (system32) is less than 4.0.1381.33577" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:307"/>
      <state state_ref="oval:org.mitre.oval:ste:424"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:462" version="1" check="at least one" comment="the version of srvsvc.dll is less than 5.1.2600.1613" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:397"/>
      <state state_ref="oval:org.mitre.oval:ste:426"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2709" version="1" check="at least one" comment="kernel version is less than 2.4.20-19.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1556"/>
      <state state_ref="oval:org.mitre.oval:ste:2530"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:463" version="1" check="at least one" comment="the version of mso.dll is less than 10.0.6714.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:398"/>
      <state state_ref="oval:org.mitre.oval:ste:427"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3056" version="1" check="at least one" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:469"/>
      <state state_ref="oval:org.mitre.oval:ste:2861"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3055" version="1" check="at least one" comment="Patch Q313450" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1747"/>
      <state state_ref="oval:org.mitre.oval:ste:2860"/>
    </registry_test>
    <file_test check="all" comment="the version of srv.sys is less than 5.2.3790.526" id="oval:org.mitre.oval:tst:97" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:133"/>
    </file_test>
    <file_test check="all" comment="the version of srv.sys is less than 5.0.2195.7087" id="oval:org.mitre.oval:tst:64" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:6"/>
    </file_test>
    <file_test check="all" comment="the version of srv.sys is less than 5.1.2600.1832" id="oval:org.mitre.oval:tst:23" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:122"/>
    </file_test>
    <file_test check="all" comment="the version of srv.sys is less than 5.2.3790.2691" id="oval:org.mitre.oval:tst:161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:157"/>
    </file_test>
    <file_test check="all" comment="the version of srv.sys is less than 5.1.2600.2893" id="oval:org.mitre.oval:tst:127" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:147"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2713" version="1" check="at least one" comment="the version of dbmslpcn.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1561"/>
      <state state_ref="oval:org.mitre.oval:ste:2534"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2712" version="1" check="at least one" comment="the version of msgprox.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1560"/>
      <state state_ref="oval:org.mitre.oval:ste:2533"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2711" version="1" check="at least one" comment="the version of replrec.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1559"/>
      <state state_ref="oval:org.mitre.oval:ste:2532"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2710" version="1" check="at least one" comment="the version of sqlvdi.dll is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1557"/>
      <state state_ref="oval:org.mitre.oval:ste:2531"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:466" version="1" check="all" comment="Patch 107684-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:351"/>
      <state state_ref="oval:org.mitre.oval:ste:430"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:465" version="1" check="all" comment="Patch 110615-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:350"/>
      <state state_ref="oval:org.mitre.oval:ste:429"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:464" version="1" check="at least one" comment="Patch 113575-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:399"/>
      <state state_ref="oval:org.mitre.oval:ste:428"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:468" version="1" check="at least one" comment="Patch 116895-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:401"/>
      <state state_ref="oval:org.mitre.oval:ste:432"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:467" version="1" check="at least one" comment="Patch 117000-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:400"/>
      <state state_ref="oval:org.mitre.oval:ste:431"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3698" version="1" check="at least one" comment="Patch 119255-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2730"/>
      <state state_ref="oval:org.mitre.oval:ste:3374"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3284" version="1" check="at least one" comment="Patch 119254-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2444"/>
      <state state_ref="oval:org.mitre.oval:ste:3922"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:3000" version="1" check="at least one" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1717"/>
      <state state_ref="oval:org.mitre.oval:ste:2811"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2714" version="1" check="at least one" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6753" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:2535"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2402" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2604" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2250"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2717" version="1" check="at least one" comment="MDAC 2.6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2538"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2716" version="1" check="at least one" comment="the version of msadco.dll is less than 2.62.9119.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:2537"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:471" version="1" check="all" comment="the software Adobe Acrobat Reader 6, major version 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:405"/>
      <state state_ref="oval:org.mitre.oval:ste:435"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:470" version="1" check="all" comment="the software Adobe Acrobat Reader 6, minor version less than 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:404"/>
      <state state_ref="oval:org.mitre.oval:ste:434"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:469" version="1" check="all" comment="Adobe Acrobat Reader eBook.api plug-in software installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:402"/>
      <state state_ref="oval:org.mitre.oval:ste:433"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2975" version="1" check="at least one" comment="Mixed Mode Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1702"/>
      <state state_ref="oval:org.mitre.oval:ste:2789"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2718" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2539"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3059" version="1" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1631"/>
      <state state_ref="oval:org.mitre.oval:ste:2864"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3058" version="1" check="at least one" comment="Patch Q321599 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1749"/>
      <state state_ref="oval:org.mitre.oval:ste:2863"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:472" version="1" check="at least one" comment="the version of ole32.dll is less than 5.1.2600.1619" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:436"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2720" version="1" check="at least one" comment="the version of msdxm.ocx is less than 6.4.9.1121" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1564"/>
      <state state_ref="oval:org.mitre.oval:ste:2541"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2719" version="1" check="at least one" comment="Patch wm308567 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1563"/>
      <state state_ref="oval:org.mitre.oval:ste:2540"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:473" version="1" check="at least one" comment="the version of psxss.exe is less than 5.0.2195.6929" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:407"/>
      <state state_ref="oval:org.mitre.oval:ste:437"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2721" version="1" check="at least one" comment="kernel version is less than 2.4.20-18.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1565"/>
      <state state_ref="oval:org.mitre.oval:ste:2542"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:476" version="1" check="at least one" comment="kernel rpm older than 2.4.21-15.0.2.EL Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:410"/>
      <state state_ref="oval:org.mitre.oval:ste:440"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:475" version="1" check="at least one" comment="kernel-hugemem rpm older than 2.4.21-15.0.2.EL Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:409"/>
      <state state_ref="oval:org.mitre.oval:ste:439"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:474" version="1" check="at least one" comment="kernel-smp rpm older than 2.4.21-15.0.2.EL Epoch 0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:408"/>
      <state state_ref="oval:org.mitre.oval:ste:438"/>
    </rpminfo_test>
    <package_test id="oval:org.mitre.oval:tst:478" version="1" check="all" comment="X Window System Font Server (SUNWxwfs) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:412"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:477" version="1" check="all" comment="Patch 113923-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:411"/>
      <state state_ref="oval:org.mitre.oval:ste:441"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2727" version="1" check="at least one" comment="Windows Media Player for Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:757"/>
      <state state_ref="oval:org.mitre.oval:ste:2548"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2726" version="1" check="at least one" comment="the version of dxmasf.dll is less than 6.4.9.1121" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1568"/>
      <state state_ref="oval:org.mitre.oval:ste:2547"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2725" version="1" check="at least one" comment="the version of msdxm.ocx is less than 6.4.9.1124" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1564"/>
      <state state_ref="oval:org.mitre.oval:ste:2546"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2724" version="1" check="at least one" comment="the version of wmpcore.dll is less than 8.0.0.4482" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1567"/>
      <state state_ref="oval:org.mitre.oval:ste:2545"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2723" version="1" check="at least one" comment="the version of wmplayer.exe is less than 8.0.0.4482" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1547"/>
      <state state_ref="oval:org.mitre.oval:ste:2544"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2722" version="1" check="at least one" comment="Patch wm320920_8.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1566"/>
      <state state_ref="oval:org.mitre.oval:ste:2543"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3061" version="1" check="at least one" comment="ddskk version is less than 11.6.0-11.90" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1751"/>
      <state state_ref="oval:org.mitre.oval:ste:2866"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3060" version="1" check="at least one" comment="ddskk-xemacs version is less than 11.6.0-11.90" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1750"/>
      <state state_ref="oval:org.mitre.oval:ste:2865"/>
    </rpminfo_test>
    <file_test check="all" comment="the version of Mso.dll is less than 11.0.8028.0." id="oval:org.mitre.oval:tst:169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:398"/>
      <state state_ref="oval:org.mitre.oval:ste:138"/>
    </file_test>
    <file_test check="all" comment="the version of Mso.dll is less than 10.0.6804.0." id="oval:org.mitre.oval:tst:141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:467"/>
      <state state_ref="oval:org.mitre.oval:ste:129"/>
    </file_test>
    <file_test check="all" comment="the version of Mso9.dll is less than 9.0.0.8944" id="oval:org.mitre.oval:tst:122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1"/>
      <state state_ref="oval:org.mitre.oval:ste:35"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2730" version="1" check="at least one" comment="the version of srvsvc.dll is less than 5.0.2195.6110" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:397"/>
      <state state_ref="oval:org.mitre.oval:ste:2551"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2729" version="1" check="at least one" comment="Patch Q329170 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1570"/>
      <state state_ref="oval:org.mitre.oval:ste:2550"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2728" version="1" check="at least one" comment="SMB Signing enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1569"/>
      <state state_ref="oval:org.mitre.oval:ste:2549"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:479" version="1" check="at least one" comment="the version of grpconv.exe (system32) is less than 5.0.2195.6966" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:307"/>
      <state state_ref="oval:org.mitre.oval:ste:442"/>
    </file_test>
    <registry_test check="at least one" comment="Visio Professional 2002 with service pack 2" id="oval:org.mitre.oval:tst:481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:414"/>
      <state state_ref="oval:org.mitre.oval:ste:444"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:480" version="1" check="at least one" comment="Patch KB873354 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:413"/>
      <state state_ref="oval:org.mitre.oval:ste:443"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:482" version="1" check="at least one" comment="the version of wins.exe is less than 4.0.1381.33618" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:445"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:483" version="1" check="at least one" comment="the version of msadco.dll is less than 2.53.6202.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:446"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2715" version="1" check="at least one" comment="Patch Q329414 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1562"/>
      <state state_ref="oval:org.mitre.oval:ste:2536"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2576" version="1" check="at least one" comment="MDAC 2.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2409"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:485" version="1" check="all" comment="Patch 113273-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:367"/>
      <state state_ref="oval:org.mitre.oval:ste:447"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:484" version="1" check="all" comment="sshd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:415"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:2732" version="1" check="at least one" comment="File sqlservr.exe version3 is less than 2000.80.578.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2553"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2731" version="1" check="at least one" comment="File xpstar.dll version3 is less than 2000.80.561.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:898"/>
      <state state_ref="oval:org.mitre.oval:ste:2552"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:486" version="1" check="at least one" comment="the version of Gdiplus.dll for Microsoft Office is less than 6.0.3264.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:416"/>
      <state state_ref="oval:org.mitre.oval:ste:448"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:488" version="1" check="at least one" comment="Windows XP or Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:419"/>
      <state state_ref="oval:org.mitre.oval:ste:450"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:86" version="1" check="at least one" comment="The version of Tcpip6.sys is less than 5.1.2600.2975" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:141"/>
      <state state_ref="oval:org.mitre.oval:ste:85"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:68" version="1" check="at least one" comment="The version of Tcpip6.sys is less than 5.1.2600.1886" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:141"/>
      <state state_ref="oval:org.mitre.oval:ste:124"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:171" version="1" check="at least one" comment="The version of Tcpip6.sys is less than 5.2.3790.576" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:141"/>
      <state state_ref="oval:org.mitre.oval:ste:40"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:131" version="1" check="at least one" comment="The version of Tcpip6.sys is less than 5.2.3790.2771" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:141"/>
      <state state_ref="oval:org.mitre.oval:ste:39"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3064" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2869"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3062" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3504.2500" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2867"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2354" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.2.3790.336" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:588"/>
      <state state_ref="oval:org.mitre.oval:ste:2204"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2736" version="1" check="at least one" comment="the version of wkssvc.dll is less than 5.1.2600.120" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1448"/>
      <state state_ref="oval:org.mitre.oval:ste:2557"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2735" version="1" check="at least one" comment="the version of wkssvc.dll is less than 5.1.2600.1301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1448"/>
      <state state_ref="oval:org.mitre.oval:ste:2556"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2734" version="1" check="at least one" comment="the version of msgsvc.dll is less than 5.1.2600.120" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1571"/>
      <state state_ref="oval:org.mitre.oval:ste:2555"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2733" version="1" check="at least one" comment="the version of msgsvc.dll is less than 5.1.2600.1301" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1571"/>
      <state state_ref="oval:org.mitre.oval:ste:2554"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:492" version="1" check="at least one" comment="the version of msconv97.dll is less than 2003.1100.6252.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:423"/>
      <state state_ref="oval:org.mitre.oval:ste:453"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:491" version="1" check="at least one" comment="the patch kb873380 for Office 2000 SP3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:422"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:490" version="1" check="at least one" comment="Microsoft Office 2000 Premium Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:421"/>
      <state state_ref="oval:org.mitre.oval:ste:452"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:489" version="1" check="at least one" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:420"/>
      <state state_ref="oval:org.mitre.oval:ste:451"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3367" version="1" check="at least one" comment="the version of umpnpmgr.dll is less than 5.1.2600.1711" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2048"/>
      <state state_ref="oval:org.mitre.oval:ste:3812"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3257" version="1" check="at least one" comment="64-Bit version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2113"/>
      <state state_ref="oval:org.mitre.oval:ste:3485"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:499" version="1" check="at least one" comment="machine has followed the GDR update path and inetcomm.dll is less than 6.0.3790.181" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:458"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:498" version="1" check="at least one" comment="machine has followed the QFE update path and inetcomm.dll is less than 6.0.3790.185" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:457"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2740" version="1" check="all" comment="gaim RPM earlier than 1:1.3.1-0.el3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1573"/>
      <state state_ref="oval:org.mitre.oval:ste:2561"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2739" version="1" check="all" comment="/usr/bin/gaim is executable by any user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1099"/>
      <state state_ref="oval:org.mitre.oval:ste:2560"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:501" version="1" check="at least one" comment="Patch 114796-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:429"/>
      <state state_ref="oval:org.mitre.oval:ste:459"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:500" version="1" check="at least one" comment="Sun Crypto Accelerator 4000 software installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:428"/>
    </package_test>
    <file_test id="oval:org.mitre.oval:tst:2741" version="1" check="at least one" comment="the version of kernel32.dll is less than 5.0.2195.6011" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:2562"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2742" version="1" check="at least one" comment="kernel version is less than 2.4.20-13.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1574"/>
      <state state_ref="oval:org.mitre.oval:ste:2563"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:3072" version="1" check="at least one" comment="the version of netman.dll is less than 5.0.2195.5974" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:658"/>
      <state state_ref="oval:org.mitre.oval:ste:2877"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3071" version="1" check="at least one" comment="Patch Q326886 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1752"/>
      <state state_ref="oval:org.mitre.oval:ste:2876"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:505" version="1" check="all" comment="Kodak Color Managment Server (KCMS) Runtime Environment (SUNWkcsrt/SUNWkcsrx) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:433"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:504" version="1" check="all" comment="Patch 114636-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:432"/>
      <state state_ref="oval:org.mitre.oval:ste:462"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:503" version="1" check="all" comment="Patch 107337-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:431"/>
      <state state_ref="oval:org.mitre.oval:ste:461"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:502" version="1" check="all" comment="Patch 111400-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:430"/>
      <state state_ref="oval:org.mitre.oval:ste:460"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:511" version="1" check="at least one" comment="Patch 113505-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:439"/>
      <state state_ref="oval:org.mitre.oval:ste:466"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:510" version="1" check="at least one" comment="Patch 113508-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:438"/>
      <state state_ref="oval:org.mitre.oval:ste:465"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:509" version="1" check="at least one" comment="Patch 115054-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:437"/>
      <state state_ref="oval:org.mitre.oval:ste:464"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:508" version="1" check="at least one" comment="Patch 115055-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:436"/>
      <state state_ref="oval:org.mitre.oval:ste:463"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:507" version="1" check="at least one" comment="SunCluster Component SUNWscvw installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:435"/>
    </package_test>
    <process_test id="oval:org.mitre.oval:tst:506" version="1" check="at least one" comment="Apache running with SunPlex Manager config" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:434"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:2746" version="1" check="all" comment="the version of srv.sys is less than 5.2.3790.324" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:2567"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:512" version="1" check="at least one" comment="the version of user32.dll is less than 5.2.3790.245" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:467"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2399" version="1" check="all" comment="the version of hlink.dll is less than 5.2.3790.227" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:391"/>
      <state state_ref="oval:org.mitre.oval:ste:2247"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2398" version="1" check="at least one" comment="the patch kb888113 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1370"/>
      <state state_ref="oval:org.mitre.oval:ste:2246"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:513" version="1" check="at least one" comment="the version of Llssrv.exe is less than 5.0.2195.7021" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:277"/>
      <state state_ref="oval:org.mitre.oval:ste:468"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2477" version="1" check="at least one" comment="the patch kb885834 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1408"/>
      <state state_ref="oval:org.mitre.oval:ste:2321"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2475" version="1" check="at least one" comment="license logging service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1407"/>
      <state state_ref="oval:org.mitre.oval:ste:2319"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2358" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.7035" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:2208"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3950" version="1" check="at least one" comment="the version of spoolsv.exe is less than 5.1.2600.2696" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2550"/>
      <state state_ref="oval:org.mitre.oval:ste:3486"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3750" version="1" check="at least one" comment="Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2535"/>
      <state state_ref="oval:org.mitre.oval:ste:3066"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3341" version="1" check="at least one" comment="Win2K/XP/2003 service pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2558"/>
      <state state_ref="oval:org.mitre.oval:ste:2951"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:515" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.279" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:469"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:514" version="1" check="at least one" comment="the patch kb890923 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:440"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:4105" version="1" check="at least one" comment="Patch 112908-12 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2309"/>
      <state state_ref="oval:org.mitre.oval:ste:3777"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:4074" version="1" check="all" comment="pam_krb5 is an auth module with debug enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:2563"/>
    </textfilecontent_test>
    <patch_test id="oval:org.mitre.oval:tst:4013" version="1" check="at least one" comment="Patch 115168-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1845"/>
      <state state_ref="oval:org.mitre.oval:ste:3539"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3957" version="1" check="at least one" comment="Patch 112908-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2309"/>
      <state state_ref="oval:org.mitre.oval:ste:3535"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:3487" version="1" check="all" comment="/etc/krb5/krb5.conf is configured as a kerberos client" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:2143"/>
    </textfilecontent_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:3394" version="1" check="all" comment="Logging of LOG_DEBUG level messages is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:1866"/>
    </textfilecontent_test>
    <patch_test id="oval:org.mitre.oval:tst:3258" version="1" check="at least one" comment="Patch 115168-03 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1845"/>
      <state state_ref="oval:org.mitre.oval:ste:3220"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:516" version="1" check="at least one" comment="the version of hypertrm.dll is less than 5.1.2600.2563" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:283"/>
      <state state_ref="oval:org.mitre.oval:ste:470"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:517" version="1" check="at least one" comment="the version of wins.exe is less than 5.0.2195.7005" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:471"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2753" version="1" check="at least one" comment="kernel version = 2.4.20-6" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1579"/>
      <state state_ref="oval:org.mitre.oval:ste:2574"/>
    </rpminfo_test>
    <uname_test id="oval:org.mitre.oval:tst:2752" version="1" check="at least one" comment="kernel 2.4.20-6 or earlier is running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2573"/>
    </uname_test>
    <file_test id="oval:org.mitre.oval:tst:519" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3534.2800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:473"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:518" version="1" check="at least one" comment="the patch kb834707-ie501sp4 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:441"/>
      <state state_ref="oval:org.mitre.oval:ste:472"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:527" version="1" check="all" comment="Kerberos v5 - Root (SUNWkrbr) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:449"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:526" version="1" check="all" comment="Kerberos v5 - Usr (SUNWkrbu/SUNWkrbux) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>SUNWkrbu - 32bit, SUNWkrbux - 64bit</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:448"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:525" version="1" check="all" comment="Patch 112237-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:447"/>
      <state state_ref="oval:org.mitre.oval:ste:479"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:524" version="1" check="all" comment="Patch 112390-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:446"/>
      <state state_ref="oval:org.mitre.oval:ste:478"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:523" version="1" check="all" comment="Patch 112925-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:445"/>
      <state state_ref="oval:org.mitre.oval:ste:477"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:522" version="1" check="all" comment="Patch 112923-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:444"/>
      <state state_ref="oval:org.mitre.oval:ste:476"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:521" version="1" check="all" comment="Patch 112921-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:443"/>
      <state state_ref="oval:org.mitre.oval:ste:475"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:520" version="1" check="all" comment="Patch 112908-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:442"/>
      <state state_ref="oval:org.mitre.oval:ste:474"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2754" version="1" check="at least one" comment="Patch Q305601 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1580"/>
      <state state_ref="oval:org.mitre.oval:ste:2575"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:528" version="1" check="at least one" comment="the version of dplayx.dll is less than 5.2.3790.163" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:480"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:530" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 4.0.1381.7299" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:482"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:529" version="1" check="at least one" comment="Patch KB873350 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:451"/>
      <state state_ref="oval:org.mitre.oval:ste:481"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:533" version="1" check="at least one" comment="the version of Sp3res.dll is less than 5.0.2195.6928" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:454"/>
      <state state_ref="oval:org.mitre.oval:ste:485"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:532" version="1" check="at least one" comment="the version of Umandlg.dll is less than 1.0.0.5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:453"/>
      <state state_ref="oval:org.mitre.oval:ste:484"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:531" version="1" check="at least one" comment="the patch kb842526 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:452"/>
      <state state_ref="oval:org.mitre.oval:ste:483"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2756" version="1" check="at least one" comment="krb5-libs version is less than 1.2.7-14" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1582"/>
      <state state_ref="oval:org.mitre.oval:ste:2577"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2755" version="1" check="at least one" comment="krb5-workstation version is less than 1.2.7-14" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1581"/>
      <state state_ref="oval:org.mitre.oval:ste:2576"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2759" version="1" check="at least one" comment="the version of nntpsvc.dll is less than 6.0.3790.206" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:252"/>
      <state state_ref="oval:org.mitre.oval:ste:2580"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2758" version="1" check="at least one" comment="the patch WindowsServer2003-KB883935-ia64-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:297"/>
      <state state_ref="oval:org.mitre.oval:ste:2579"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2757" version="1" check="at least one" comment="the NNTP service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1583"/>
      <state state_ref="oval:org.mitre.oval:ste:2578"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:535" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.219" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:487"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:534" version="1" check="at least one" comment="the patch kb834707 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:455"/>
      <state state_ref="oval:org.mitre.oval:ste:486"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:537" version="1" check="all" comment="Indexing Service ciodm.dll is less than 5.1.2600.1596" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:457"/>
      <state state_ref="oval:org.mitre.oval:ste:488"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:536" version="1" check="at least one" comment="the patch Windows XP KB871250 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:456"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:547" version="1" check="all" comment="NIS Server - User (SUNWypu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>Package which contains /usr/lib/netsvc/yp/ypxfrd</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:462"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:546" version="1" check="all" comment="Patch 106541-24 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:291"/>
      <state state_ref="oval:org.mitre.oval:ste:494"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:545" version="1" check="all" comment="Patch 109328-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:461"/>
      <state state_ref="oval:org.mitre.oval:ste:493"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:544" version="1" check="all" comment="Patch 113579-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:460"/>
      <state state_ref="oval:org.mitre.oval:ste:492"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:543" version="1" check="all" comment="ypxfrd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:459"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:548" version="1" check="at least one" comment="the version of dplayx.dll is less than 5.2.3790.163 on 64-bit edition" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:463"/>
      <state state_ref="oval:org.mitre.oval:ste:495"/>
    </file_test>
    <metabase_test id="oval:org.mitre.oval:tst:3074" version="1" check="at least one" comment="FTP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1753"/>
      <state state_ref="oval:org.mitre.oval:ste:2879"/>
    </metabase_test>
    <file_test id="oval:org.mitre.oval:tst:550" version="1" check="at least one" comment="the version of nddenb32.dll is less than 4.0.1381.7268" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:464"/>
      <state state_ref="oval:org.mitre.oval:ste:497"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:549" version="1" check="at least one" comment="the version of netdde.exe is less than 4.0.1381.7280" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:393"/>
      <state state_ref="oval:org.mitre.oval:ste:496"/>
    </file_test>
    <registry_test check="at least one" comment="Publisher 2003 is installed" id="oval:org.mitre.oval:tst:24" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:158"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:551" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.168" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:498"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:552" version="1" check="at least one" comment="The patch KB885492 is installed on Windows 2000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:465"/>
      <state state_ref="oval:org.mitre.oval:ste:499"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2764" version="1" check="at least one" comment="the version of tshoot.ocx is less than 1.0.1.2125" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1586"/>
      <state state_ref="oval:org.mitre.oval:ste:2585"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2763" version="1" check="at least one" comment="the patch kb826232 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1585"/>
      <state state_ref="oval:org.mitre.oval:ste:2584"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2780" version="1" check="at least one" comment="File console.exe version3 is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1596"/>
      <state state_ref="oval:org.mitre.oval:ste:2601"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2779" version="1" check="at least one" comment="File dbmslpcn.dll version3 is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1561"/>
      <state state_ref="oval:org.mitre.oval:ste:2600"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2778" version="1" check="at least one" comment="File sqlmap70.dll version3 is less than 2000.80.811.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1595"/>
      <state state_ref="oval:org.mitre.oval:ste:2599"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2777" version="1" check="at least one" comment="File sqlrepss.dll version3 is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1594"/>
      <state state_ref="oval:org.mitre.oval:ste:2598"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2776" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2597"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2775" version="1" check="at least one" comment="the version of ssmslpcn.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1593"/>
      <state state_ref="oval:org.mitre.oval:ste:2596"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2774" version="1" check="at least one" comment="the version of ssnetlib.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:841"/>
      <state state_ref="oval:org.mitre.oval:ste:2595"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2773" version="1" check="at least one" comment="the version of ssnmpn70.dll is less than 2000.80.818.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1592"/>
      <state state_ref="oval:org.mitre.oval:ste:2594"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2772" version="1" check="at least one" comment="the version of ums.dll is less than 2000.80.816.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1591"/>
      <state state_ref="oval:org.mitre.oval:ste:2593"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2771" version="1" check="at least one" comment="the version of odsole70.dll is less than 2000.80.800.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:903"/>
      <state state_ref="oval:org.mitre.oval:ste:2592"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2770" version="1" check="at least one" comment="the version of xpweb70.dll is less than 2000.80.778.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:899"/>
      <state state_ref="oval:org.mitre.oval:ste:2591"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2769" version="1" check="at least one" comment="File msgprox.dll version3 is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1590"/>
      <state state_ref="oval:org.mitre.oval:ste:2590"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2768" version="1" check="at least one" comment="the version of replprov.dll is less than 2000.80.798.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1589"/>
      <state state_ref="oval:org.mitre.oval:ste:2589"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2767" version="1" check="at least one" comment="File replrec.dll version3 is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1588"/>
      <state state_ref="oval:org.mitre.oval:ste:2588"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2766" version="1" check="at least one" comment="File sqlvdi.dll version3 is less than 2000.80.765.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1587"/>
      <state state_ref="oval:org.mitre.oval:ste:2587"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:554" version="1" check="at least one" comment="the version of mso.dll is less than 10.0.6735.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:467"/>
      <state state_ref="oval:org.mitre.oval:ste:501"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:553" version="1" check="at least one" comment="Patch KB873355 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:466"/>
      <state state_ref="oval:org.mitre.oval:ste:500"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:556" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.109" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:503"/>
    </file_test>
    <registry_test check="at least one" comment="Excel 2002 is installed" id="oval:org.mitre.oval:tst:2420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1377"/>
    </registry_test>
    <file_test check="all" comment="Excel Viewer is installed." id="oval:org.mitre.oval:tst:61" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:659"/>
    </file_test>
    <file_test check="all" comment="the version of excel.exe is less than 9.0.0.8946" id="oval:org.mitre.oval:tst:6" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:194"/>
    </file_test>
    <file_test check="all" comment="the version of excel.exe is less than 10.0.6809.0" id="oval:org.mitre.oval:tst:53" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:183"/>
    </file_test>
    <file_test check="all" comment="the version of excel.exe is less than 11.0.8033.0" id="oval:org.mitre.oval:tst:18" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:174"/>
    </file_test>
    <file_test check="all" comment="the version of xlview.exe is less than 11.0.8033.0." id="oval:org.mitre.oval:tst:128" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:659"/>
      <state state_ref="oval:org.mitre.oval:ste:174"/>
    </file_test>
    <registry_test check="at least one" comment="Microsoft Office 2003 is installed" id="oval:org.mitre.oval:tst:487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:418"/>
      <state state_ref="oval:org.mitre.oval:ste:449"/>
    </registry_test>
    <file_test check="all" comment="the version of dhcpcsvc.dll is less than 5.2.3790.536" id="oval:org.mitre.oval:tst:82" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:115"/>
      <state state_ref="oval:org.mitre.oval:ste:141"/>
    </file_test>
    <file_test check="all" comment="the version of dhcpcsvc.dll is less than 5.1.2600.2912" id="oval:org.mitre.oval:tst:5" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:115"/>
      <state state_ref="oval:org.mitre.oval:ste:1"/>
    </file_test>
    <file_test check="all" comment="the version of dhcpcsvc.dll is less than 5.0.2195.7085" id="oval:org.mitre.oval:tst:186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:115"/>
      <state state_ref="oval:org.mitre.oval:ste:92"/>
    </file_test>
    <file_test check="all" comment="the version of dhcpcsvc.dll is less than 5.1.2600.1847" id="oval:org.mitre.oval:tst:105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:115"/>
      <state state_ref="oval:org.mitre.oval:ste:121"/>
    </file_test>
    <file_test check="all" comment="the version of dhcpcsvc.dll is less than 5.2.3790.2706" id="oval:org.mitre.oval:tst:103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:115"/>
      <state state_ref="oval:org.mitre.oval:ste:171"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2966" version="1" check="at least one" comment="File sqlservr.exe version3 greater than or equal to 2000.80.384.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2780"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2784" version="1" check="at least one" comment="File odsole70.dll Version3 is less than 2000.80.223.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:903"/>
      <state state_ref="oval:org.mitre.oval:ste:2605"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2783" version="1" check="at least one" comment="File xpqueue.dll Version3 is less than 2000.80.223.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:902"/>
      <state state_ref="oval:org.mitre.oval:ste:2604"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2782" version="1" check="at least one" comment="File xprepl.dll Version3 is less than 2000.80.223.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:901"/>
      <state state_ref="oval:org.mitre.oval:ste:2603"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2781" version="1" check="at least one" comment="File xpstar.dll Version3 is less than 2000.80.223.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:898"/>
      <state state_ref="oval:org.mitre.oval:ste:2602"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:558" version="1" check="at least one" comment="The version of smtpsvc.dll is less than 6.0.3790.211" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:469"/>
      <state state_ref="oval:org.mitre.oval:ste:505"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:557" version="1" check="at least one" comment="the patch WindowsServer2003-KB885881-x86-enu.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:378"/>
      <state state_ref="oval:org.mitre.oval:ste:504"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3054" version="1" check="at least one" comment="SMTP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1746"/>
      <state state_ref="oval:org.mitre.oval:ste:2859"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2760" version="1" check="all" comment="Exchange Server 2003 (gold edition) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1584"/>
      <state state_ref="oval:org.mitre.oval:ste:2581"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2785" version="1" check="at least one" comment="krb5-server version is less than 1.2.7-14" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1597"/>
      <state state_ref="oval:org.mitre.oval:ste:2606"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:3075" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4725.2100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2880"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:560" version="1" check="at least one" comment="the version of srvsvc.dll is less than 5.1.2600.2577" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:397"/>
      <state state_ref="oval:org.mitre.oval:ste:507"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:559" version="1" check="at least one" comment="the patch kb888302 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:470"/>
      <state state_ref="oval:org.mitre.oval:ste:506"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:562" version="1" check="at least one" comment="the version of Dhcpssvc.dll is less than 4.0.1381.7304" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:304"/>
      <state state_ref="oval:org.mitre.oval:ste:509"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:561" version="1" check="at least one" comment="the patch KB885249 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:471"/>
      <state state_ref="oval:org.mitre.oval:ste:508"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:564" version="1" check="all" comment="Windows Messenger 5.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:473"/>
      <state state_ref="oval:org.mitre.oval:ste:511"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:563" version="1" check="all" comment="the version of msmsgs.exe is less than 5.1.0.639" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:472"/>
      <state state_ref="oval:org.mitre.oval:ste:510"/>
    </file_test>
    <registry_test check="at least one" comment="IIS Major Version equals 6" id="oval:org.mitre.oval:tst:170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1754"/>
      <state state_ref="oval:org.mitre.oval:ste:195"/>
    </registry_test>
    <registry_test check="at least one" comment="IIS Minor Version equals 0" id="oval:org.mitre.oval:tst:164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:938"/>
      <state state_ref="oval:org.mitre.oval:ste:165"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:565" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33545" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:512"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:567" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3826.2400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:514"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:566" version="1" check="at least one" comment="the patch kb890923 is installed (Win2K SP4  Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:474"/>
      <state state_ref="oval:org.mitre.oval:ste:513"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2786" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4922.900" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2607"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:581" version="1" check="at least one" comment="Patch 108748-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:487"/>
      <state state_ref="oval:org.mitre.oval:ste:527"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:580" version="1" check="at least one" comment="Patch 108750-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:486"/>
      <state state_ref="oval:org.mitre.oval:ste:526"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:579" version="1" check="at least one" comment="Patch 108752-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:485"/>
      <state state_ref="oval:org.mitre.oval:ste:525"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:578" version="1" check="at least one" comment="Patch 106541-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:291"/>
      <state state_ref="oval:org.mitre.oval:ste:524"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:577" version="1" check="at least one" comment="Patch 106942-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:484"/>
      <state state_ref="oval:org.mitre.oval:ste:523"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:576" version="1" check="at least one" comment="Patch 107477-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:483"/>
      <state state_ref="oval:org.mitre.oval:ste:522"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:575" version="1" check="at least one" comment="Patch 108551-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:482"/>
      <state state_ref="oval:org.mitre.oval:ste:521"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:574" version="1" check="at least one" comment="Patch 108754-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:481"/>
      <state state_ref="oval:org.mitre.oval:ste:520"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:573" version="1" check="at least one" comment="Patch 108756-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:480"/>
      <state state_ref="oval:org.mitre.oval:ste:519"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:572" version="1" check="at least one" comment="Patch 108758-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:479"/>
      <state state_ref="oval:org.mitre.oval:ste:518"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:571" version="1" check="at least one" comment="Patch 108760-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:478"/>
      <state state_ref="oval:org.mitre.oval:ste:517"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:570" version="1" check="at least one" comment="Patch 108762-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:477"/>
      <state state_ref="oval:org.mitre.oval:ste:516"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:569" version="1" check="at least one" comment="Patch 108764-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>CVE-2002-1265</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:476"/>
      <state state_ref="oval:org.mitre.oval:ste:515"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:568" version="1" check="at least one" comment="rpcbind running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:475"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:582" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1556" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:528"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:587" version="1" check="all" comment="Sendmail - user (SUNWsndmu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:489"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:586" version="1" check="all" comment="Patch 107684-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:351"/>
      <state state_ref="oval:org.mitre.oval:ste:531"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:585" version="1" check="all" comment="Patch 110615-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:350"/>
      <state state_ref="oval:org.mitre.oval:ste:530"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:584" version="1" check="all" comment="Patch 113575-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:399"/>
      <state state_ref="oval:org.mitre.oval:ste:529"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:583" version="1" check="at least one" comment="Sendmail running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:488"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:98" check="all" comment="The version of mso.dll is less than 11.0.8107.0." version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:398"/>
      <state state_ref="oval:org.mitre.oval:ste:65"/>
    </file_test>
    <file_test check="all" comment="The Office 2003 (or later) version of Mso.dll is installed." id="oval:org.mitre.oval:tst:69" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:398"/>
      <state state_ref="oval:org.mitre.oval:ste:126"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:33" check="all" comment="The version of mso9.dll is less than 9.0.0.8950." version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1"/>
      <state state_ref="oval:org.mitre.oval:ste:193"/>
    </file_test>
    <file_test check="all" comment="The Office 2000 (or later) version of Mso9.dll is installed." id="oval:org.mitre.oval:tst:194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1"/>
      <state state_ref="oval:org.mitre.oval:ste:107"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:158" check="all" comment="The version of mso.dll is less than 10.0.6817.0." version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:467"/>
      <state state_ref="oval:org.mitre.oval:ste:29"/>
    </file_test>
    <file_test check="all" comment="The Office 2002 (or later) version of Mso.dll is installed." id="oval:org.mitre.oval:tst:139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:467"/>
      <state state_ref="oval:org.mitre.oval:ste:7"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:590" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2745.2800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:534"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:589" version="1" check="at least one" comment="the patch kb834707 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:491"/>
      <state state_ref="oval:org.mitre.oval:ste:533"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:588" version="1" check="at least one" comment="Users not saving encrypted pages to disk  (DisableCachingOfSSLPages)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:490"/>
      <state state_ref="oval:org.mitre.oval:ste:532"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:591" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8929" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:535"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:49" version="1" check="at least one" comment="Microsoft XML Core Services 5 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:47"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:182" version="1" check="at least one" comment="Microsoft XML Core Services 6 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:190"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:179" version="1" check="at least one" comment="Microsoft XML Core Services 3 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:3"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:87" version="1" check="at least one" comment="The version of Msxml5.dll is less than 5.10.2930.0." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:47"/>
      <state state_ref="oval:org.mitre.oval:ste:199"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:72" version="1" check="at least one" comment="The version of Msxml4.dll is less than 4.20.9839.0." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:191"/>
      <state state_ref="oval:org.mitre.oval:ste:60"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:34" version="1" check="at least one" comment="The version of Msxml3.dll is less than 8.70.1113.0." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:3"/>
      <state state_ref="oval:org.mitre.oval:ste:28"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:32" version="1" check="at least one" comment="The version of Msxml6.dll is less than 6.0.3888.0." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:190"/>
      <state state_ref="oval:org.mitre.oval:ste:150"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:50" version="1" check="at least one" comment="the version of powerpnt.exe is less than 10.0.6819.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:553"/>
      <state state_ref="oval:org.mitre.oval:ste:9"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:184" version="1" check="at least one" comment="the version of powerpnt.exe is less than 11.0.8110.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:553"/>
      <state state_ref="oval:org.mitre.oval:ste:23"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:165" version="1" check="at least one" comment="the version of powerpnt.exe is less than 9.0.0.8952" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:553"/>
      <state state_ref="oval:org.mitre.oval:ste:56"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:605" version="1" check="at least one" comment="the version of dplayx.dll is less than 5.2.3677.144" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:549"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:604" version="1" check="at least one" comment="DirectX 8.2 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:548"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:603" version="1" check="at least one" comment="Patch DirectX82-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:501"/>
      <state state_ref="oval:org.mitre.oval:ste:547"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:602" version="1" check="at least one" comment="the version of dplayx.dll is less than 5.3.0.903" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:546"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:601" version="1" check="at least one" comment="DirectX 9.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:545"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:600" version="1" check="at least one" comment="Patch DirectX90-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:500"/>
      <state state_ref="oval:org.mitre.oval:ste:544"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:599" version="1" check="at least one" comment="the version of dplayx.dll is less than 5.1.2600.148" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:543"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:598" version="1" check="at least one" comment="DirectX 8.1x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:542"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:597" version="1" check="at least one" comment="the patch kb839643 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:498"/>
      <state state_ref="oval:org.mitre.oval:ste:541"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:596" version="1" check="at least one" comment="the version of dplayx.dll is less than 5.1.2600.1517" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:540"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:3955" version="1" check="at least one" comment="Solaris 10 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2733"/>
      <state state_ref="oval:org.mitre.oval:ste:3839"/>
    </uname_test>
    <isainfo_test id="oval:org.mitre.oval:tst:3884" version="1" check="at least one" comment="system is running in 64-bit mode" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2704"/>
      <state state_ref="oval:org.mitre.oval:ste:3528"/>
    </isainfo_test>
    <uname_test id="oval:org.mitre.oval:tst:3338" version="1" check="at least one" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2733"/>
      <state state_ref="oval:org.mitre.oval:ste:3040"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:3195" version="1" check="at least one" comment="Patch 118844-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2090"/>
      <state state_ref="oval:org.mitre.oval:ste:3384"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2352" version="1" check="all" comment="Enable Path MTU Discovery is Disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1347"/>
      <state state_ref="oval:org.mitre.oval:ste:2202"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:606" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1643" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:550"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2542" version="1" check="at least one" comment="the patch  KB893086 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1449"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:608" version="1" check="at least one" comment="Sendmail - root (SUNWsndmr) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:502"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:607" version="1" check="all" comment="Patch 113575-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:399"/>
      <state state_ref="oval:org.mitre.oval:ste:551"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2788" version="1" check="at least one" comment="the version of quartz.dll is less than 6.1.5.132" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1599"/>
      <state state_ref="oval:org.mitre.oval:ste:2609"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2787" version="1" check="at least one" comment="Patch Q19696 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1598"/>
      <state state_ref="oval:org.mitre.oval:ste:2608"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2792" version="1" check="at least one" comment="the version of itircl.dll is less than 5.2.3790.80" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1531"/>
      <state state_ref="oval:org.mitre.oval:ste:2612"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2791" version="1" check="at least one" comment="Patch KB825119 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1600"/>
      <state state_ref="oval:org.mitre.oval:ste:2611"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2789" version="1" check="at least one" comment="HCP Protocol" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1001"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:612" version="1" check="at least one" comment="the patch kb841872 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:504"/>
      <state state_ref="oval:org.mitre.oval:ste:554"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:611" version="1" check="at least one" comment="the version of psxss.exe is less than 4.0.1381.33567" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:407"/>
      <state state_ref="oval:org.mitre.oval:ste:553"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:610" version="1" check="at least one" comment="the version of psxss.exe is less than 4.0.1381.7269" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:407"/>
      <state state_ref="oval:org.mitre.oval:ste:552"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:609" version="2" check="at least one" comment="POSIX is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:503"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:615" version="1" check="all" comment="Samba (SUNWsmbar) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:507"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:614" version="1" check="all" comment="Patch 114684-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:506"/>
      <state state_ref="oval:org.mitre.oval:ste:556"/>
    </patch_test>
    <inetd_test id="oval:org.mitre.oval:tst:613" version="1" check="all" comment="inetd.conf contains smbd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:505"/>
      <state state_ref="oval:org.mitre.oval:ste:555"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:2793" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3819.300" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2613"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:616" version="1" check="at least one" comment="Patch 112908-15 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:442"/>
      <state state_ref="oval:org.mitre.oval:ste:557"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:617" version="1" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4942.400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:558"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2798" version="1" check="at least one" comment="the version of msgsvc.dll is less than 5.0.2195.6861" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1571"/>
      <state state_ref="oval:org.mitre.oval:ste:2618"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2797" version="1" check="at least one" comment="the version of wkssvc.dll is less than 5.0.2195.6861" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1448"/>
      <state state_ref="oval:org.mitre.oval:ste:2617"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2796" version="1" check="at least one" comment="the patch q828035 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1602"/>
      <state state_ref="oval:org.mitre.oval:ste:2616"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2795" version="1" check="at least one" comment="the messenger service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1601"/>
      <state state_ref="oval:org.mitre.oval:ste:2615"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:619" version="1" check="all" comment="Indexing Service ciodm.dll is less than 5.2.3790.220" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:457"/>
      <state state_ref="oval:org.mitre.oval:ste:559"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:618" version="1" check="at least one" comment="the patch Windows 2003 KB871250 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:508"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:620" version="1" check="at least one" comment="the version of gdi32.dll is less than 5.0.2195.6945" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:279"/>
      <state state_ref="oval:org.mitre.oval:ste:560"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:3901" version="1" check="all" comment="HP Release B.11.23" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3324"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:3439" version="1" check="at least one" comment="Patch PHNE_32606 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2081"/>
      <state state_ref="oval:org.mitre.oval:ste:3930"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:621" version="1" check="at least one" comment="the version of winword.exe is less than 10.0.6754.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:561"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2762" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4943.400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2583"/>
    </file_test>
    <registry_test check="all" comment="MS Project 2000 is installed." id="oval:org.mitre.oval:tst:77" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:124"/>
      <state state_ref="oval:org.mitre.oval:ste:5"/>
    </registry_test>
    <file_test check="all" comment="the version of Gifimp32.flt is less than 2003.1100.8020.0." id="oval:org.mitre.oval:tst:67" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2"/>
      <state state_ref="oval:org.mitre.oval:ste:96"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:623" version="1" check="all" comment="Patch 106938-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:313"/>
      <state state_ref="oval:org.mitre.oval:ste:563"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:622" version="1" check="all" comment="Patch 109326-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:312"/>
      <state state_ref="oval:org.mitre.oval:ste:562"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:2626" version="1" check="all" comment="Internet Domain Name Server (BIND, SUNWinamd) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1497"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:2625" version="1" check="all" comment="Patch 112970-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:311"/>
      <state state_ref="oval:org.mitre.oval:ste:2453"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:625" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3821.2800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:565"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:624" version="1" check="at least one" comment="the patch kb834707-ie501sp3 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:509"/>
      <state state_ref="oval:org.mitre.oval:ste:564"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2800" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.191" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2620"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2799" version="1" check="at least one" comment="the patch kb867801 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1603"/>
      <state state_ref="oval:org.mitre.oval:ste:2619"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:626" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8943" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:566"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:630" version="1" check="at least one" comment="Patch 112908-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:442"/>
      <state state_ref="oval:org.mitre.oval:ste:568"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:629" version="1" check="at least one" comment="Patch 112908-12 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:442"/>
      <state state_ref="oval:org.mitre.oval:ste:567"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:628" version="1" check="all" comment="/etc/pam.conf is configured to use pam_krb5 as an 'auth' module and the debug feature of pam_krb5 is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:511"/>
    </textfilecontent_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:627" version="1" check="all" comment="/etc/syslog.conf is configured to log &quot;debug&quot; level messages for at least daemon" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:510"/>
    </textfilecontent_test>
    <file_test id="oval:org.mitre.oval:tst:631" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.1.2600.1597" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:569"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3063" version="1" check="at least one" comment="Internet Explorer 5.01 Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2868"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2803" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3532.300" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2623"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2804" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.6328" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2624"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:632" version="1" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.7009" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:570"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:633" version="1" check="all" comment="cdoex.dll is less than 6.5.7233.69" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:513"/>
      <state state_ref="oval:org.mitre.oval:ste:571"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:635" version="1" check="all" comment="Patch 112300-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:515"/>
      <state state_ref="oval:org.mitre.oval:ste:573"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:634" version="1" check="all" comment="Patch 111085-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:514"/>
      <state state_ref="oval:org.mitre.oval:ste:572"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2805" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.6926" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2625"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:638" version="1" check="at least one" comment="the version of cdo.dll is less than 5.5.2558.10" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:518"/>
      <state state_ref="oval:org.mitre.oval:ste:575"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:637" version="1" check="at least one" comment="the  patch kb842436 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:517"/>
      <state state_ref="oval:org.mitre.oval:ste:574"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:636" version="1" check="at least one" comment="Outlook Web Access exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:516"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2492" version="1" check="at least one" comment="Exchange 5.5 with SP4 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:732"/>
      <state state_ref="oval:org.mitre.oval:ste:2333"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:642" version="1" check="at least one" comment="Patch 106938-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:313"/>
      <state state_ref="oval:org.mitre.oval:ste:578"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:641" version="1" check="at least one" comment="Patch 109326-13 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:312"/>
      <state state_ref="oval:org.mitre.oval:ste:577"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:640" version="1" check="at least one" comment="Patch 112970-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:311"/>
      <state state_ref="oval:org.mitre.oval:ste:576"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:639" version="1" check="all" comment="Core Solaris (SUNWcsu/SUNWcsxu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <oval-def:notes>
        <oval-def:note>SUNWcsu = 32bit, SUNWcsxu = 64bit</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:519"/>
    </package_test>
    <process_test id="oval:org.mitre.oval:tst:2624" version="1" check="at least one" comment="in.named running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1496"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:2810" version="1" check="at least one" comment="the version of user32.dll is less than 5.1.2600.118" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:2630"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2809" version="1" check="at least one" comment="the version of user32.dll is less than 5.1.2600.1255" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:2629"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2808" version="1" check="at least one" comment="the patch kb824141 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1607"/>
      <state state_ref="oval:org.mitre.oval:ste:2628"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2806" version="1" check="at least one" comment="the utility manager Service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1605"/>
      <state state_ref="oval:org.mitre.oval:ste:2626"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:648" version="1" check="at least one" comment="Kerberos 5 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:521"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:647" version="1" check="at least one" comment="Patch 112908-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:442"/>
      <state state_ref="oval:org.mitre.oval:ste:582"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:646" version="1" check="at least one" comment="Patch 112536-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:296"/>
      <state state_ref="oval:org.mitre.oval:ste:581"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:645" version="1" check="at least one" comment="Patch 112237-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:447"/>
      <state state_ref="oval:org.mitre.oval:ste:580"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:644" version="1" check="at least one" comment="Patch 112390-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:446"/>
      <state state_ref="oval:org.mitre.oval:ste:579"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:643" version="1" check="all" comment="/etc/krb5/krb5.conf is configured with explicit or rules-based mapping" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:520"/>
    </textfilecontent_test>
    <file_test id="oval:org.mitre.oval:tst:3083" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.0.2195.6810" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:2888"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3151" version="1" check="at least one" comment="balsa version is less than 2.0.6-2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1791"/>
      <state state_ref="oval:org.mitre.oval:ste:2947"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:3150" version="1" check="at least one" comment="/usr/bin/balsa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1790"/>
      <state state_ref="oval:org.mitre.oval:ste:2946"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3149" version="1" check="at least one" comment="/usr/bin/balsa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1790"/>
      <state state_ref="oval:org.mitre.oval:ste:2945"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3148" version="1" check="at least one" comment="/usr/bin/balsa is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1790"/>
      <state state_ref="oval:org.mitre.oval:ste:2944"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:650" version="1" check="at least one" comment="The version of Ipnathlp.dll is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:522"/>
      <state state_ref="oval:org.mitre.oval:ste:584"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:649" version="1" check="at least one" comment="The version of Ipnathlp.dll is less than 5.1.2600.1364" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:522"/>
      <state state_ref="oval:org.mitre.oval:ste:583"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:651" version="1" check="all" comment="cdoex.dll is less than 6.5.7650.29" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:513"/>
      <state state_ref="oval:org.mitre.oval:ste:585"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2816" version="1" check="at least one" comment="Terminal Server Version" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1612"/>
      <state state_ref="oval:org.mitre.oval:ste:2636"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2815" version="1" check="at least one" comment="File %windir%\system32\drivers\rdpwd.sys version is less than 5.0.2195.5880" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:220"/>
      <state state_ref="oval:org.mitre.oval:ste:2635"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2814" version="1" check="at least one" comment="Patch Q324380 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1611"/>
      <state state_ref="oval:org.mitre.oval:ste:2634"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2813" version="1" check="at least one" comment="RDP Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1610"/>
      <state state_ref="oval:org.mitre.oval:ste:2633"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:652" version="1" check="at least one" comment="the version of PowerPnt.exe is less than 9.0.0.8942" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:523"/>
      <state state_ref="oval:org.mitre.oval:ste:586"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:656" version="1" check="at least one" comment="Patch 116973-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:217"/>
      <state state_ref="oval:org.mitre.oval:ste:588"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:655" version="1" check="at least one" comment="Patch 113146-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:215"/>
      <state state_ref="oval:org.mitre.oval:ste:587"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:653" version="1" check="at least one" comment="Apache (SUNWapchu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:525"/>
    </package_test>
    <file_test id="oval:org.mitre.oval:tst:2817" version="1" check="at least one" comment="File %windir%\system32\cryptui.dll version is less than 5.131.2195.6758" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1613"/>
      <state state_ref="oval:org.mitre.oval:ste:2637"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:657" version="1" check="all" comment="the version of mrxsmb.sys is less than 5.1.2600.1836" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:589"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:658" version="1" check="at least one" comment="the version of wmp.dll is less than 10.0.0.3704" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:527"/>
      <state state_ref="oval:org.mitre.oval:ste:590"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:661" version="1" check="all" comment="FTP Server - Usr (SUNWftpu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:530"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:660" version="1" check="all" comment="Patch 114564-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:529"/>
      <state state_ref="oval:org.mitre.oval:ste:592"/>
    </patch_test>
    <inetd_test id="oval:org.mitre.oval:tst:659" version="1" check="all" comment="inetd.conf contains in.ftpd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:528"/>
      <state state_ref="oval:org.mitre.oval:ste:591"/>
    </inetd_test>
    <registry_test id="oval:org.mitre.oval:tst:2990" version="1" check="at least one" comment="Windows 2000 Security Roll-up 1 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1710"/>
      <state state_ref="oval:org.mitre.oval:ste:2803"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2820" version="1" check="at least one" comment="File %windir%\system32\idq.dll version is less than 5.0.2195.3645" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1616"/>
      <state state_ref="oval:org.mitre.oval:ste:2640"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2819" version="1" check="at least one" comment="Patch Q300972 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1615"/>
      <state state_ref="oval:org.mitre.oval:ste:2639"/>
    </registry_test>
    <metabase_test id="oval:org.mitre.oval:tst:2818" version="1" check="at least one" comment="idq.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1614"/>
      <state state_ref="oval:org.mitre.oval:ste:2638"/>
    </metabase_test>
    <file_test id="oval:org.mitre.oval:tst:663" version="1" check="at least one" comment="the version of mstask.dll is less than 5.1.2600.155" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:379"/>
      <state state_ref="oval:org.mitre.oval:ste:594"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:662" version="1" check="at least one" comment="the version of mstask.dll is less than 5.1.2600.1564" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:379"/>
      <state state_ref="oval:org.mitre.oval:ste:593"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:664" version="1" check="at least one" comment="the version of hhctrl.ocx is less than 5.2.3790.1280" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:531"/>
      <state state_ref="oval:org.mitre.oval:ste:595"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:665" version="1" check="at least one" comment="The version of ipnathlp.dll is less than 5.2.3790.142" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:522"/>
      <state state_ref="oval:org.mitre.oval:ste:596"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:666" version="1" check="at least one" comment="the version of wordpad.exe is less than 5.1.2600.1606" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:389"/>
      <state state_ref="oval:org.mitre.oval:ste:597"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:669" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2800.1441" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:600"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:668" version="1" check="at least one" comment="the patch kb823353 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:533"/>
      <state state_ref="oval:org.mitre.oval:ste:599"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:667" version="1" check="at least one" comment="all users have the preview pane disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:532"/>
      <state state_ref="oval:org.mitre.oval:ste:598"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2822" version="1" check="at least one" comment="Patch Q823980 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1617"/>
      <state state_ref="oval:org.mitre.oval:ste:2642"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2821" version="1" check="at least one" comment="the version of rpcss.dll is less than 4.0.1381.7224" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:2641"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2826" version="1" check="at least one" comment="kdebase version is less than 3.1-15" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1619"/>
      <state state_ref="oval:org.mitre.oval:ste:2646"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2825" version="1" check="at least one" comment="/usr/bin/kdm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1618"/>
      <state state_ref="oval:org.mitre.oval:ste:2645"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2824" version="1" check="at least one" comment="/usr/bin/kdm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1618"/>
      <state state_ref="oval:org.mitre.oval:ste:2644"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2823" version="1" check="at least one" comment="/usr/bin/kdm is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1618"/>
      <state state_ref="oval:org.mitre.oval:ste:2643"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2827" version="1" check="at least one" comment="Patch 110286-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1620"/>
      <state state_ref="oval:org.mitre.oval:ste:2647"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:670" version="1" check="at least one" comment="the version of Msdtctm.dll is less than 2001.12.4414.311" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:534"/>
      <state state_ref="oval:org.mitre.oval:ste:601"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3021" version="1" check="at least one" comment="Patch Q277873 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1729"/>
      <state state_ref="oval:org.mitre.oval:ste:2829"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2828" version="1" check="at least one" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2784" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:496"/>
      <state state_ref="oval:org.mitre.oval:ste:2648"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:671" version="1" check="at least one" comment="the version of rasmans.dll is less than 5.1.2600.1842" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:535"/>
      <state state_ref="oval:org.mitre.oval:ste:602"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:674" version="1" check="at least one" comment="Patch 107702-12 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:538"/>
      <state state_ref="oval:org.mitre.oval:ste:605"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:673" version="1" check="at least one" comment="Patch 109354-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:537"/>
      <state state_ref="oval:org.mitre.oval:ste:604"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:672" version="1" check="at least one" comment="Patch 114497-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:536"/>
      <state state_ref="oval:org.mitre.oval:ste:603"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2831" version="1" check="at least one" comment="the version of xenroll.dll is less than 5.131.3659.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1622"/>
      <state state_ref="oval:org.mitre.oval:ste:2651"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2830" version="1" check="at least one" comment="Patch Q323172 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1621"/>
      <state state_ref="oval:org.mitre.oval:ste:2650"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2829" version="1" check="at least one" comment="ActiveX Enabled In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:988"/>
      <state state_ref="oval:org.mitre.oval:ste:2649"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3086" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2716.2200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2891"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:676" version="1" check="at least one" comment="the version of Swflash.ocx is the original shipped with XP,SP1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:540"/>
      <state state_ref="oval:org.mitre.oval:ste:606"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2834" version="1" check="at least one" comment="the version of xactsrv.dll is less than 5.0.2195.5971" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1625"/>
      <state state_ref="oval:org.mitre.oval:ste:2654"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2833" version="1" check="at least one" comment="Patch Q326830 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1624"/>
      <state state_ref="oval:org.mitre.oval:ste:2653"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2832" version="1" check="at least one" comment="Lanman enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1623"/>
      <state state_ref="oval:org.mitre.oval:ste:2652"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:677" version="1" check="at least one" comment="the version of mrxsmb.sys is less than 5.1.2600.1620" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:607"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:678" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1605" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:541"/>
      <state state_ref="oval:org.mitre.oval:ste:608"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:680" version="1" check="at least one" comment="CDE Daemons (SUNWdtdmn) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:543"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:679" version="1" check="at least one" comment="Patch 108221-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:542"/>
      <state state_ref="oval:org.mitre.oval:ste:609"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2835" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.7924" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2655"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:681" version="1" check="at least one" comment="the version of vdmdbg.dll is less than 5.1.2600.1560" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:302"/>
      <state state_ref="oval:org.mitre.oval:ste:610"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:684" version="1" check="at least one" comment="the version of nddenb32.dll is less than 4.0.1381.33565" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:464"/>
      <state state_ref="oval:org.mitre.oval:ste:613"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:683" version="1" check="at least one" comment="the version of netdde.exe is less than 4.0.1381.33574" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:393"/>
      <state state_ref="oval:org.mitre.oval:ste:612"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:682" version="1" check="at least one" comment="the patch KB841533 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:544"/>
      <state state_ref="oval:org.mitre.oval:ste:611"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:685" version="1" check="all" comment="the version of mrxsmb.sys is less than 5.0.2195.7097" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:614"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2844" version="1" check="at least one" comment="the version of cryptui.dll is less than 5.131.2600.117" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1613"/>
      <state state_ref="oval:org.mitre.oval:ste:2663"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2842" version="1" check="at least one" comment="the version of cryptui.dll is less than 5.131.2600.1243" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1613"/>
      <state state_ref="oval:org.mitre.oval:ste:2661"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2841" version="1" check="at least one" comment="Patch WindowsXP-KB823182-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1629"/>
      <state state_ref="oval:org.mitre.oval:ste:2660"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2840" version="1" check="at least one" comment="downloading of signed ActiveX controls is enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1628"/>
      <state state_ref="oval:org.mitre.oval:ste:2659"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2839" version="1" check="at least one" comment="downloading of signed ActiveX controls is enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1627"/>
      <state state_ref="oval:org.mitre.oval:ste:2658"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:686" version="1" check="at least one" comment="the version of mrxsmb.sys is less than 5.2.3790.252" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:615"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:690" version="1" check="all" comment="NIS/NIS+ Utilities installed (SUNWnisu)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:547"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:689" version="1" check="all" comment="Patch 108750-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:486"/>
      <state state_ref="oval:org.mitre.oval:ste:617"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:688" version="1" check="all" comment="Patch 110322-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:546"/>
      <state state_ref="oval:org.mitre.oval:ste:616"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:687" version="1" check="all" comment="ypbind running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:545"/>
    </process_test>
    <file_test id="oval:org.mitre.oval:tst:691" version="1" check="at least one" comment="the version of grpconv.exe is less than 5.1.2600.166" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:307"/>
      <state state_ref="oval:org.mitre.oval:ste:618"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:692" version="1" check="all" comment="the version of mrxsmb.sys is less than 5.1.2600.2902" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:619"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:700" version="1" check="at least one" comment="Patch 108993-14 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:275"/>
      <state state_ref="oval:org.mitre.oval:ste:627"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:699" version="1" check="at least one" comment="Patch 108993-51 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:275"/>
      <state state_ref="oval:org.mitre.oval:ste:626"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:698" version="1" check="at least one" comment="Patch 115677-02 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:552"/>
      <state state_ref="oval:org.mitre.oval:ste:625"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:697" version="1" check="at least one" comment="Patch 121321-01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:551"/>
      <state state_ref="oval:org.mitre.oval:ste:624"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:696" version="1" check="at least one" comment="Patch 108994-14 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:550"/>
      <state state_ref="oval:org.mitre.oval:ste:623"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:695" version="1" check="at least one" comment="Patch 108994-51 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:550"/>
      <state state_ref="oval:org.mitre.oval:ste:622"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:694" version="1" check="at least one" comment="Patch 115678-02 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:549"/>
      <state state_ref="oval:org.mitre.oval:ste:621"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:693" version="1" check="at least one" comment="Patch 121322-01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:548"/>
      <state state_ref="oval:org.mitre.oval:ste:620"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:702" version="1" check="at least one" comment="the version of grpconv.exe is less than 5.1.2600.1580" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:307"/>
      <state state_ref="oval:org.mitre.oval:ste:629"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:701" version="1" check="at least one" comment="the version of grpconv.exe (syswow64) is less than 5.1.2600.1580" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:292"/>
      <state state_ref="oval:org.mitre.oval:ste:628"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:704" version="1" check="at least one" comment="PowerPoint 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:555"/>
      <state state_ref="oval:org.mitre.oval:ste:631"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:703" version="2" check="at least one" comment="the version of PowerPnt.exe is less than 10.0.6800.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:553"/>
      <state state_ref="oval:org.mitre.oval:ste:630"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:705" version="1" check="at least one" comment="the version of rasmans.dll is less than 5.1.2600.2908" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:535"/>
      <state state_ref="oval:org.mitre.oval:ste:632"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:706" version="1" check="at least one" comment="the version of wmp.dll is less than 9.0.0.3349" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:527"/>
      <state state_ref="oval:org.mitre.oval:ste:633"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2847" version="1" check="at least one" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1631"/>
      <state state_ref="oval:org.mitre.oval:ste:2665"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2846" version="1" check="at least one" comment="Patch Q321599 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1630"/>
      <state state_ref="oval:org.mitre.oval:ste:2664"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:707" version="1" check="all" comment="cdoex.dll is less than 6.0.6618.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:513"/>
      <state state_ref="oval:org.mitre.oval:ste:634"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:708" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.1.2600.1254" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:635"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:710" version="1" check="at least one" comment="The version of Ipnathlp.dll is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:557"/>
      <state state_ref="oval:org.mitre.oval:ste:636"/>
    </file_test>
    <metabase_test id="oval:org.mitre.oval:tst:709" version="1" check="at least one" comment="Negotiate is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:556"/>
    </metabase_test>
    <file_test id="oval:org.mitre.oval:tst:711" version="1" check="at least one" comment="the version of wmpui.dll is less than 8.0.0.4496" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:558"/>
      <state state_ref="oval:org.mitre.oval:ste:637"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:712" version="1" check="at least one" comment="the version of wwmp.dll is less than 10.0.0.3704" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:559"/>
      <state state_ref="oval:org.mitre.oval:ste:638"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3652" version="1" check="at least one" comment="Win2K/XP/2003 service pack 4 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2558"/>
      <state state_ref="oval:org.mitre.oval:ste:3711"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3633" version="1" check="at least one" comment="the version of rdpwd.sys is less than 5.0.2195.7055" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2219"/>
      <state state_ref="oval:org.mitre.oval:ste:3781"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3381" version="1" check="at least one" comment="Windows 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2535"/>
      <state state_ref="oval:org.mitre.oval:ste:3492"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3088" version="1" check="at least one" comment="the version of shell32.dll is less than 4.0.1381.7116" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:2893"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:713" version="1" check="at least one" comment="the version of winword.exe is less than 11.0.6502.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:639"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2583" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2743.600" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2416"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:714" version="1" check="all" comment="the version of mrxsmb.sys is less than 5.2.3790.529" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:640"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1632" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.3790.2663" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1484"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:717" version="1" check="at least one" comment="The version of Firefox.exe is greater than or equal to 1.8.20060.42618 (v1.5.0.3)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:561"/>
      <state state_ref="oval:org.mitre.oval:ste:643"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:716" version="1" check="at least one" comment="Mozilla Firefox version 1.5.0.2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:560"/>
      <state state_ref="oval:org.mitre.oval:ste:642"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:715" version="1" check="at least one" comment="Firefox version 1.5.0.2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:641"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2964" version="1" check="at least one" comment="File lbxproxy exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1696"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2962" version="1" check="at least one" comment="File lbxproxy SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1696"/>
      <state state_ref="oval:org.mitre.oval:ste:2777"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2961" version="1" check="at least one" comment="File lbxproxy SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1696"/>
      <state state_ref="oval:org.mitre.oval:ste:2776"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2848" version="1" check="at least one" comment="Patch 107654-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1632"/>
      <state state_ref="oval:org.mitre.oval:ste:2666"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:718" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.0.2195.7087" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:644"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:719" version="1" check="at least one" comment="the version of Jscript.dll is greater than or equal to 5.6.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:645"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:721" version="1" check="at least one" comment="the version of mstask.dll is less than 5.1.2600.1555" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:379"/>
      <state state_ref="oval:org.mitre.oval:ste:647"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:720" version="1" check="at least one" comment="Patch Windows2000-kb841873-x86-enu.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:565"/>
      <state state_ref="oval:org.mitre.oval:ste:646"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:723" version="2" check="at least one" comment="Outlook Express 5.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:566"/>
      <state state_ref="oval:org.mitre.oval:ste:649"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:722" version="1" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4963.1700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:648"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3078" version="1" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2883"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3077" version="1" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2882"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3076" version="1" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2881"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3013" version="1" check="at least one" comment="the patch q813489 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1725"/>
      <state state_ref="oval:org.mitre.oval:ste:2822"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2849" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4923.2500" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2667"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:729" version="1" check="at least one" comment="MDAC 2.5 (SP3) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:655"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:728" version="1" check="at least one" comment="the version of msadco.dll is less than 2.53.6306.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:654"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:727" version="1" check="at least one" comment="the version of msadco.dll is less than 2.71.9053.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:653"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:726" version="1" check="at least one" comment="the version of msadco.dll is less than 2.80.1062.0000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:652"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:725" version="1" check="at least one" comment="MDAC 2.8 (SP1) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:651"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:724" version="1" check="at least one" comment="the version of msadco.dll is less than 2.81.1124.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:650"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2382" version="1" check="at least one" comment="MDAC 2.7 (SP1) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2231"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2363" version="1" check="at least one" comment="MDAC 2.8 (RTM) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2213"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:730" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.2.3790.537" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:656"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:731" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.3790.504" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:657"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2850" version="1" check="at least one" comment="Patch 107893-20 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:301"/>
      <state state_ref="oval:org.mitre.oval:ste:2668"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:732" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.3790.2663" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:658"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:733" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.503" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:659"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:734" version="1" check="all" comment="the version of rpcrt4.dll is less than 5.0.2195.7085" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:660"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:736" version="1" check="at least one" comment="Patch PHNE_34544 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:568"/>
      <state state_ref="oval:org.mitre.oval:ste:662"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:735" version="1" check="at least one" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.008 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:567"/>
      <state state_ref="oval:org.mitre.oval:ste:661"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:3393" version="1" check="at least one" comment="Patch PHNE_33395 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1973"/>
      <state state_ref="oval:org.mitre.oval:ste:3269"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:737" version="1" check="at least one" comment="Patch PHCO_34545 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:569"/>
      <state state_ref="oval:org.mitre.oval:ste:663"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:738" version="1" check="at least one" comment="the version of win32k.sys is less than 5.2.3790.198" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:570"/>
      <state state_ref="oval:org.mitre.oval:ste:664"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2356" version="1" check="at least one" comment="the patch KB840987 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1349"/>
      <state state_ref="oval:org.mitre.oval:ste:2206"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:743" version="1" check="at least one" comment="Active Desktop  is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:572"/>
      <state state_ref="oval:org.mitre.oval:ste:669"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:742" version="1" check="at least one" comment="the version of shell32.dll is less than 4.72.3843.3100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:668"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:741" version="1" check="at least one" comment="the version of shell32.dll is less than 4.0.1381.7267" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:667"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:740" version="1" check="at least one" comment="the version of shell32.dll is less than 4.0.1381.3356" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:666"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:739" version="1" check="at least one" comment="the patch q841356 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:571"/>
      <state state_ref="oval:org.mitre.oval:ste:665"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:744" version="1" check="at least one" comment="the version of fpadmdll.dll is less than 10.0.6790.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:573"/>
      <state state_ref="oval:org.mitre.oval:ste:670"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:745" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.3790.2662" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:671"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:746" version="1" check="at least one" comment="the version of msadco.dll is less than 2.82.2644.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:672"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:747" version="1" check="at least one" comment="the version of rasmans.dll is less than 5.0.2195.7093" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:535"/>
      <state state_ref="oval:org.mitre.oval:ste:673"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:4152" version="1" check="at least one" comment="OS-Core.ARRAY-MGMT (B.11.11) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2380"/>
      <state state_ref="oval:org.mitre.oval:ste:3011"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3830" version="1" check="at least one" comment="OS-Core.ADMN-ENG-A-MAN (B.11.11) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2623"/>
      <state state_ref="oval:org.mitre.oval:ste:3226"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:3210" version="1" check="at least one" comment="Patch PHCO_23263 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2700"/>
      <state state_ref="oval:org.mitre.oval:ste:3819"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:748" version="1" check="at least one" comment="the version of winword.exe is less than 10.0.6802.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:674"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:749" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3528.700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:675"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:753" version="1" check="all" comment="SunSoft Print - Client - Usr (SUNWpcu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:575"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:752" version="1" check="at least one" comment="Patch 107115-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:300"/>
      <state state_ref="oval:org.mitre.oval:ste:678"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:751" version="1" check="at least one" comment="Patch 109320-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:315"/>
      <state state_ref="oval:org.mitre.oval:ste:677"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:750" version="1" check="at least one" comment="Patch 113329-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:314"/>
      <state state_ref="oval:org.mitre.oval:ste:676"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:754" version="1" check="at least one" comment="the version of wmp.dll is less than 10.0.0.4036" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:527"/>
      <state state_ref="oval:org.mitre.oval:ste:679"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:756" version="1" check="at least one" comment="Microsoft Visual Studio .NET 2003 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:578"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:755" version="1" check="at least one" comment="the version of Gdiplus.dll for Visual Studio .NET is less than 5.1.3102.1355" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:576"/>
      <state state_ref="oval:org.mitre.oval:ste:680"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:757" version="1" check="at least one" comment="the version of rasmans.dll is less than 5.2.3790.529" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:535"/>
      <state state_ref="oval:org.mitre.oval:ste:681"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:759" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7265" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:683"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:758" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.33563" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:682"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:760" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.2.3790.2709" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:684"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:95" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:26"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:56" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:36"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:175" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:149"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:11"/>
    </file_test>
    <file_test check="all" comment="The version of dnsapi.dll is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:178"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:762" version="1" check="at least one" comment="Sun Enterprise Storage Manager installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:580"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:761" version="1" check="at least one" comment="Patch 117367-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:579"/>
      <state state_ref="oval:org.mitre.oval:ste:685"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:763" version="1" check="all" comment="the version of wdhtmled.ocx is less than 6.1.0.9232" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:280"/>
      <state state_ref="oval:org.mitre.oval:ste:686"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:4070" version="1" check="at least one" comment="Patch 112669-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2288"/>
      <state state_ref="oval:org.mitre.oval:ste:3850"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:4005" version="1" check="at least one" comment="Patch 112668-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1949"/>
      <state state_ref="oval:org.mitre.oval:ste:3228"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3778" version="1" check="at least one" comment="Patch 116341-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2548"/>
      <state state_ref="oval:org.mitre.oval:ste:3562"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3666" version="1" check="at least one" comment="Patch 116340-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2010"/>
      <state state_ref="oval:org.mitre.oval:ste:3405"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3621" version="1" check="at least one" comment="Patch 120720-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2637"/>
      <state state_ref="oval:org.mitre.oval:ste:3667"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3295" version="1" check="at least one" comment="Patch 120719-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2345"/>
      <state state_ref="oval:org.mitre.oval:ste:3869"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3091" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2713.1100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2896"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:765" version="1" check="at least one" comment="Patch 118966-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:581"/>
      <state state_ref="oval:org.mitre.oval:ste:688"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:764" version="1" check="at least one" comment="Patch 118966-17 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:581"/>
      <state state_ref="oval:org.mitre.oval:ste:687"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:766" version="1" check="at least one" comment="Patch WinXP-KB914798 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:582"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:768" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2627" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:689"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:767" version="1" check="at least one" comment="the patch kb890923  is installed (XP SP2 Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:583"/>
    </registry_test>
    <swlist_test id="oval:org.mitre.oval:tst:771" version="1" check="at least one" comment="OS-Core.UX2-CORE is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:586"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:770" version="1" check="at least one" comment="Patch PHCO_32149 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:585"/>
      <state state_ref="oval:org.mitre.oval:ste:691"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:769" version="1" check="at least one" comment="Patch PHCO_32926 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:584"/>
      <state state_ref="oval:org.mitre.oval:ste:690"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2852" version="1" check="at least one" comment="httpd version is less than 2.0.40-21.5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1634"/>
      <state state_ref="oval:org.mitre.oval:ste:2670"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2851" version="1" check="at least one" comment="httpd.worker is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1633"/>
      <state state_ref="oval:org.mitre.oval:ste:2669"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:774" version="1" check="all" comment="sendmail before 8.12.x is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:694"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:773" version="1" check="all" comment="sendmail 8.12.x before 8.12.11 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:693"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:772" version="1" check="all" comment="sendmail 8.13.x before 8.13.6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:587"/>
      <state state_ref="oval:org.mitre.oval:ste:692"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:776" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.1.2600.1693" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:588"/>
      <state state_ref="oval:org.mitre.oval:ste:696"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:775" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.1.2600.2685" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:588"/>
      <state state_ref="oval:org.mitre.oval:ste:695"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:778" version="1" check="at least one" comment="Patch 108528-27 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:290"/>
      <state state_ref="oval:org.mitre.oval:ste:698"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:777" version="1" check="at least one" comment="Patch 112233-12 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:289"/>
      <state state_ref="oval:org.mitre.oval:ste:697"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:779" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2800.1807" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:699"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:780" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2800.1816" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:700"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:781" version="1" check="at least one" comment="Patch S03-KB914798 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:589"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2854" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.3790.326" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:2672"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:782" version="1" check="at least one" comment="the version of Wjgdw400.dll is less than 106.0.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:590"/>
      <state state_ref="oval:org.mitre.oval:ste:701"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:783" version="1" check="at least one" comment="the version of Imekr61.ime is less than 6.1.2600.3 (WinXP)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:591"/>
      <state state_ref="oval:org.mitre.oval:ste:702"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:784" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.1.2600.1792 (XP,SP1)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:703"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:786" version="1" check="at least one" comment="Windows Media Player 9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:593"/>
      <state state_ref="oval:org.mitre.oval:ste:705"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:785" version="1" check="at least one" comment="the version of Wmp.dll is less than 9.0.0.3344" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:592"/>
      <state state_ref="oval:org.mitre.oval:ste:704"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:788" version="1" check="at least one" comment="Patch PHCO_33214 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:595"/>
      <state state_ref="oval:org.mitre.oval:ste:707"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:787" version="1" check="at least one" comment="Patch PHCO_33215 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:594"/>
      <state state_ref="oval:org.mitre.oval:ste:706"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2738" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.2622" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:2559"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2570" version="1" check="at least one" comment="the version of wordpad.exe is less than 5.2.3790.224" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:389"/>
      <state state_ref="oval:org.mitre.oval:ste:2403"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:790" version="1" check="all" comment="GNU Zip (gzip, SUNWgzip) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:597"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:789" version="1" check="all" comment="Patch 112668-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:596"/>
      <state state_ref="oval:org.mitre.oval:ste:708"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:791" version="1" check="at least one" comment="the version of Imekr61.ime is less than 6.1.3790.1 (S03-Gold)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:591"/>
      <state state_ref="oval:org.mitre.oval:ste:709"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2431" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.2.3790.2617 (64-bit,SP1)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:2278"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:792" version="1" check="at least one" comment="the version of Jscript.dll is less than 5.1.0.12512" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:710"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2860" version="1" check="all" comment="openssl-perl is older than 0.9.7a-33.15" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1639"/>
      <state state_ref="oval:org.mitre.oval:ste:2678"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2859" version="1" check="all" comment="openssl-devel older than 0.9.7a-33.15" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1638"/>
      <state state_ref="oval:org.mitre.oval:ste:2677"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2858" version="1" check="all" comment="openssl older than 0.9.7a-33.15" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1637"/>
      <state state_ref="oval:org.mitre.oval:ste:2676"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2857" version="1" check="all" comment="openssl096b package is older than 0.9.6b-16.22.3.i386.rpm" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1636"/>
      <state state_ref="oval:org.mitre.oval:ste:2675"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2856" version="1" check="all" comment="/tmp is writable by everyone" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1420"/>
      <state state_ref="oval:org.mitre.oval:ste:2674"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:793" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3837.1200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:711"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:795" version="1" check="at least one" comment="InternetSrvcs.INETSVCS2-RUN (B.11.22) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:599"/>
      <state state_ref="oval:org.mitre.oval:ste:713"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:794" version="1" check="at least one" comment="Patch PHNE_29462 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:598"/>
      <state state_ref="oval:org.mitre.oval:ste:712"/>
    </patch_test>
    <registry_test check="at least one" comment="Windows Project Professional 2002 Service Pack 1 is installed" id="oval:org.mitre.oval:tst:555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:468"/>
      <state state_ref="oval:org.mitre.oval:ste:502"/>
    </registry_test>
    <registry_test check="all" comment="Microsoft Office XP is installed" id="oval:org.mitre.oval:tst:2327" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1339"/>
      <state state_ref="oval:org.mitre.oval:ste:2179"/>
    </registry_test>
    <file_test check="all" comment="the version of Gifimp32.flt is less than 2003.1100.8020.0." id="oval:org.mitre.oval:tst:7" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:66"/>
      <state state_ref="oval:org.mitre.oval:ste:30"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:801" version="1" check="at least one" comment="Patch 109764-06 or later installed (SPARC-8)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:605"/>
      <state state_ref="oval:org.mitre.oval:ste:719"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:800" version="1" check="at least one" comment="Patch 116047-03 or later installed (SPARC-9)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:604"/>
      <state state_ref="oval:org.mitre.oval:ste:718"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:799" version="1" check="at least one" comment="Patch 119596-03 or later installed (SPARC-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:603"/>
      <state state_ref="oval:org.mitre.oval:ste:717"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:798" version="1" check="at least one" comment="Patch 109765-06 or later installed (x86-8)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:602"/>
      <state state_ref="oval:org.mitre.oval:ste:716"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:797" version="1" check="at least one" comment="Patch 121995-01 or later installed (x86-9)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:601"/>
      <state state_ref="oval:org.mitre.oval:ste:715"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:796" version="1" check="at least one" comment="Patch 118813-03 or later installed (x86-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:600"/>
      <state state_ref="oval:org.mitre.oval:ste:714"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:802" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1555" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:720"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:808" version="1" check="at least one" comment="Patch 117350-33 or later installed (SPARC-8)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:611"/>
      <state state_ref="oval:org.mitre.oval:ste:726"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:807" version="1" check="at least one" comment="Patch 118558-22 or later installed (SPARC-9)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:610"/>
      <state state_ref="oval:org.mitre.oval:ste:725"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:806" version="1" check="at least one" comment="Patch 118822-29 or later installed (SPARC-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:609"/>
      <state state_ref="oval:org.mitre.oval:ste:724"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:805" version="1" check="at least one" comment="Patch 117351-33 or later installed (x86-8)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:608"/>
      <state state_ref="oval:org.mitre.oval:ste:723"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:804" version="1" check="at least one" comment="Patch 118559-22 or later installed (x86-9)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:607"/>
      <state state_ref="oval:org.mitre.oval:ste:722"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:803" version="1" check="at least one" comment="Patch 118844-29 or later installed (x86-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:606"/>
      <state state_ref="oval:org.mitre.oval:ste:721"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:818" version="1" check="all" comment="Gnome 2.0.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:621"/>
    </textfilecontent_test>
    <patch_test id="oval:org.mitre.oval:tst:817" version="1" check="at least one" comment="Patch 114644-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:620"/>
      <state state_ref="oval:org.mitre.oval:ste:733"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:816" version="1" check="at least one" comment="Patch 114645-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:619"/>
      <state state_ref="oval:org.mitre.oval:ste:732"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:815" version="1" check="at least one" comment="Patch 114686-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:618"/>
      <state state_ref="oval:org.mitre.oval:ste:731"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:814" version="1" check="all" comment="Gnome 2.0.2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:617"/>
    </textfilecontent_test>
    <patch_test id="oval:org.mitre.oval:tst:813" version="1" check="at least one" comment="Patch 115738-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:616"/>
      <state state_ref="oval:org.mitre.oval:ste:730"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:812" version="1" check="at least one" comment="Patch 114687-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:615"/>
      <state state_ref="oval:org.mitre.oval:ste:729"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:811" version="1" check="at least one" comment="Patch 115739-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:614"/>
      <state state_ref="oval:org.mitre.oval:ste:728"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:810" version="1" check="all" comment="JDS release 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:613"/>
    </textfilecontent_test>
    <patch_test id="oval:org.mitre.oval:tst:809" version="1" check="at least one" comment="Patch 121092-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:612"/>
      <state state_ref="oval:org.mitre.oval:ste:727"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:819" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.2.3790.462" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:734"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:820" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.0.2900.2869" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:735"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1633" version="2" check="at least one" comment="Outlook Express 6.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:566"/>
      <state state_ref="oval:org.mitre.oval:ste:1485"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2960" version="1" check="at least one" comment="the version of snmp.exe is less than 4.0.1381.7134" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:2775"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:821" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2912" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:736"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:822" version="1" check="at least one" comment="Patch 118822-24 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:609"/>
      <state state_ref="oval:org.mitre.oval:ste:737"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:2409" version="1" check="at least one" comment="Patch 118844-24 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:606"/>
      <state state_ref="oval:org.mitre.oval:ste:2257"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:823" version="1" check="at least one" comment="Patch PHNE_33159 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:623"/>
      <state state_ref="oval:org.mitre.oval:ste:738"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:825" version="1" check="at least one" comment="the version of mrxsmb.sys is less than 5.1.2600.2598" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:740"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:824" version="1" check="at least one" comment="the patch KB885250 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:624"/>
      <state state_ref="oval:org.mitre.oval:ste:739"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:829" version="1" check="at least one" comment="the version of hypertrm.dll is less than 5.1.2600.1609" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:283"/>
      <state state_ref="oval:org.mitre.oval:ste:742"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:828" version="1" check="at least one" comment="the patch WindowsXP-KB87339-x86-ENU.exe is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:627"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:827" version="1" check="none exist" comment="If key present hyperterminal will automatically open session files" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:626"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:826" version="1" check="all" comment="If the Hyperterminal client is registered as the default telnet client" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:625"/>
      <state state_ref="oval:org.mitre.oval:ste:741"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:830" version="1" check="at least one" comment="the version of webclnt.dll is less than 5.1.2600.2821 (XP,SP2)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:628"/>
      <state state_ref="oval:org.mitre.oval:ste:743"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:831" version="1" check="at least one" comment="Windows ME Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:629"/>
      <state state_ref="oval:org.mitre.oval:ste:744"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:4033" version="1" check="at least one" comment="Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2535"/>
      <state state_ref="oval:org.mitre.oval:ste:3591"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3535" version="1" check="at least one" comment="the version of umpnpmgr.dll is less than 5.2.3790.2477" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2048"/>
      <state state_ref="oval:org.mitre.oval:ste:3916"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3342" version="1" check="at least one" comment="Win2K/XP/2003 service pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:2558"/>
      <state state_ref="oval:org.mitre.oval:ste:3833"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:833" version="1" check="at least one" comment="Windows Media Player 10 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:630"/>
      <state state_ref="oval:org.mitre.oval:ste:746"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:832" version="1" check="at least one" comment="the version of Wmp.dll is less than 10.0.0.4019" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:592"/>
      <state state_ref="oval:org.mitre.oval:ste:745"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:834" version="1" check="at least one" comment="the version of Imekr61.ime is less than 6.2.2551.0 (64-bit)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:591"/>
      <state state_ref="oval:org.mitre.oval:ste:747"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:835" version="1" check="at least one" comment="the version of jgdw400.dll is less than 106.0.0.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:631"/>
      <state state_ref="oval:org.mitre.oval:ste:748"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2862" version="1" check="at least one" comment="the version of netlogon.dll is less than 4.0.1381.7092" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1640"/>
      <state state_ref="oval:org.mitre.oval:ste:2680"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:836" version="1" check="at least one" comment="the version of rasmans.dll is less than 5.2.3790.2697" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:535"/>
      <state state_ref="oval:org.mitre.oval:ste:749"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:837" version="1" check="at least one" comment="Patch PHCO_32280 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:632"/>
      <state state_ref="oval:org.mitre.oval:ste:750"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:838" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.1.2600.2892" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:751"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:841" version="1" check="at least one" comment="SysMgmtServer.MX-PORTAL (C.04.00.00.00) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:635"/>
      <state state_ref="oval:org.mitre.oval:ste:754"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:840" version="1" check="at least one" comment="SysMgmtServer.MX-PORTAL (C.04.01.00.00) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:634"/>
      <state state_ref="oval:org.mitre.oval:ste:753"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:842" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.2.3790.220" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:755"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:845" version="1" check="at least one" comment="Patch 120329-02 or later installed (SPARC-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:638"/>
      <state state_ref="oval:org.mitre.oval:ste:757"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:844" version="1" check="at least one" comment="Patch 120330-02 or later installed (SPARC-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:637"/>
      <state state_ref="oval:org.mitre.oval:ste:756"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:843" version="1" check="all" comment="Target is configured to reference pam_krb5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:636"/>
    </textfilecontent_test>
    <registry_test id="oval:org.mitre.oval:tst:2972" version="1" check="at least one" comment="Patch Q320206 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1700"/>
      <state state_ref="oval:org.mitre.oval:ste:2786"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2863" version="1" check="at least one" comment="the version of smss.exe is less than 4.0.1381.7152" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1641"/>
      <state state_ref="oval:org.mitre.oval:ste:2681"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:846" version="1" check="at least one" comment="the version of Wmpui.dll is less than 7.10.0.3077" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:639"/>
      <state state_ref="oval:org.mitre.oval:ste:758"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:847" version="1" check="at least one" comment="Patch PHCO_29249 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:640"/>
      <state state_ref="oval:org.mitre.oval:ste:759"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:849" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:642"/>
      <state state_ref="oval:org.mitre.oval:ste:761"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:848" version="1" check="at least one" comment="Patch PHNE_33792 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:641"/>
      <state state_ref="oval:org.mitre.oval:ste:760"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:2472" version="1" check="at least one" comment="InternetSrvcs.INETSVCS2-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1404"/>
      <state state_ref="oval:org.mitre.oval:ste:2316"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:852" version="1" check="at least one" comment="OS-Core.CORE-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:645"/>
      <state state_ref="oval:org.mitre.oval:ste:764"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:851" version="1" check="at least one" comment="OS-Core.UX-CORE is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:644"/>
      <state state_ref="oval:org.mitre.oval:ste:763"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:850" version="1" check="at least one" comment="Patch PHCO_33967 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:643"/>
      <state state_ref="oval:org.mitre.oval:ste:762"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:853" version="1" check="at least one" comment="The patch KB885492 is installed on Windows Server 2003" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:465"/>
      <state state_ref="oval:org.mitre.oval:ste:765"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:854" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.1.2600.1789" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:766"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:856" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1476" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:768"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:855" version="1" check="at least one" comment="the patch kb834707 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:646"/>
      <state state_ref="oval:org.mitre.oval:ste:767"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:857" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6992" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:769"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:858" version="1" check="at least one" comment="the version of Npdsplay.dll is less than 3.0.2.629" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:647"/>
      <state state_ref="oval:org.mitre.oval:ste:770"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:859" version="1" check="at least one" comment="the version of Flash.ocx is less than 7.0.19.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:648"/>
      <state state_ref="oval:org.mitre.oval:ste:771"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:861" version="1" check="at least one" comment="PowerPoint 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:649"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:860" version="1" check="at least one" comment="the version of PowerPnt.exe is less than 9.0.0.8936" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:523"/>
      <state state_ref="oval:org.mitre.oval:ste:772"/>
    </file_test>
    <registry_test check="all" comment="Microsoft Office 2000 is installed" id="oval:org.mitre.oval:tst:863" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:650"/>
    </registry_test>
    <file_test check="at least one" comment="the version of Winword.exe is less than 9.0.0.8938" id="oval:org.mitre.oval:tst:862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:773"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:1442" version="1" check="at least one" comment="Networking.NET2-KRN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:984"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:864" version="1" check="all" comment="shell32.dll is less than 6.0.3790.2534" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:775"/>
    </file_test>
    <file_test check="all" comment="The version of Kernel32.dll is less than 5.0.2195.7099." id="oval:org.mitre.oval:tst:80" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:162"/>
    </file_test>
    <file_test check="all" comment="The version of Kernel32.dll is less than 5.2.3790.556." id="oval:org.mitre.oval:tst:63" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:104"/>
    </file_test>
    <file_test check="all" comment="The version of Kernel32.dll is less than 5.1.2600.2945." id="oval:org.mitre.oval:tst:45" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:153"/>
    </file_test>
    <file_test check="all" comment="The version of Kernel32.dll is less than 5.1.2600.1869." id="oval:org.mitre.oval:tst:31" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:192"/>
    </file_test>
    <file_test check="all" comment="The version of Kernel32.dll is less than 5.2.3790.2741." id="oval:org.mitre.oval:tst:104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1549"/>
      <state state_ref="oval:org.mitre.oval:ste:158"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:866" version="1" check="at least one" comment="the version of wins.exe is less than 5.2.3790.239" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:276"/>
      <state state_ref="oval:org.mitre.oval:ste:777"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:865" version="1" check="at least one" comment="the patch KB870763 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:651"/>
      <state state_ref="oval:org.mitre.oval:ste:776"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2405" version="1" check="at least one" comment="the wins service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1372"/>
      <state state_ref="oval:org.mitre.oval:ste:2253"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:867" version="1" check="at least one" comment="the version of webclnt.dll is less than 5.2.3790.453 (S03-Gold)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:628"/>
      <state state_ref="oval:org.mitre.oval:ste:778"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:868" version="1" check="all" comment="nwwks.dll is less than 5.2.3790.386" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:652"/>
      <state state_ref="oval:org.mitre.oval:ste:779"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:869" version="1" check="at least one" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.004 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:653"/>
      <state state_ref="oval:org.mitre.oval:ste:780"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:871" version="1" check="all" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1522" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:782"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:870" version="1" check="all" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1523" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:781"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:872" version="1" check="all" comment="shell32.dll is less than 6.0.3790.413" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:783"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:873" version="1" check="all" comment="nwwks.dll is less than 5.0.2195.7065" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:652"/>
      <state state_ref="oval:org.mitre.oval:ste:784"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:874" version="1" check="all" comment="mshtml.dll is less than 5.0.3833.200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:785"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:878" version="1" check="at least one" comment="Patch 111570-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:657"/>
      <state state_ref="oval:org.mitre.oval:ste:789"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:877" version="1" check="at least one" comment="Patch 111571-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:656"/>
      <state state_ref="oval:org.mitre.oval:ste:788"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:876" version="1" check="at least one" comment="Patch 113322-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:655"/>
      <state state_ref="oval:org.mitre.oval:ste:787"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:875" version="1" check="at least one" comment="Patch 115880-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:654"/>
      <state state_ref="oval:org.mitre.oval:ste:786"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:879" version="1" check="all" comment="netman.dll is less than 5.1.2600.2743" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:658"/>
      <state state_ref="oval:org.mitre.oval:ste:790"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:880" version="1" check="at least one" comment="Patch 110943-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:322"/>
      <state state_ref="oval:org.mitre.oval:ste:791"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:881" version="1" check="at least one" comment="Xlview.exe is installed with a version less than 11.0.8012.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:659"/>
      <state state_ref="oval:org.mitre.oval:ste:792"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2864" version="1" check="at least one" comment="Patch 108117-06 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1642"/>
      <state state_ref="oval:org.mitre.oval:ste:2682"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:882" version="1" check="all" comment="umpnpmgr.dll is less than 5.1.2600.2744" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:224"/>
      <state state_ref="oval:org.mitre.oval:ste:793"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:883" version="1" check="all" comment="shell32.dll is less than 6.0.2900.2763" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:794"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:884" version="1" check="all" comment="cdosys.dll is less than 6.2.4.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:661"/>
      <state state_ref="oval:org.mitre.oval:ste:795"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:885" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:796"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:886" version="1" check="at least one" comment="the version of msadco.dll is less than 2.71.9053.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:797"/>
    </file_test>
    <registry_test check="at least one" comment="Excel 2003 is installed" id="oval:org.mitre.oval:tst:888" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:664"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:887" version="2" check="at least one" comment="the version of excel.exe is less than 11.0.8012.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:798"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2866" version="1" check="at least one" comment="httpd version is less than 2.0.40-21.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1644"/>
      <state state_ref="oval:org.mitre.oval:ste:2684"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:2865" version="1" check="at least one" comment="httpd listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1643"/>
      <state state_ref="oval:org.mitre.oval:ste:2683"/>
    </inetlisteningservers_test>
    <file_test id="oval:org.mitre.oval:tst:3105" version="1" check="at least one" comment="File rpc.ttdbserverd exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1762"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3104" version="1" check="at least one" comment="Patch 110286-09 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1620"/>
      <state state_ref="oval:org.mitre.oval:ste:2909"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3102" version="1" check="at least one" comment="File rpc.ttdbserverd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1762"/>
      <state state_ref="oval:org.mitre.oval:ste:2907"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3101" version="1" check="at least one" comment="File rpc.ttdbserverd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1762"/>
      <state state_ref="oval:org.mitre.oval:ste:2906"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3100" version="1" check="at least one" comment="File rpc.ttdbserverd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1762"/>
      <state state_ref="oval:org.mitre.oval:ste:2905"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:890" version="1" check="at least one" comment="Webproxy is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:666"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:889" version="1" check="at least one" comment="Patch PHSS_34163 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:665"/>
      <state state_ref="oval:org.mitre.oval:ste:799"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2445" version="1" check="at least one" comment="Mozilla Firefox pre-1.5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1388"/>
      <state state_ref="oval:org.mitre.oval:ste:2290"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2444" version="1" check="at least one" comment="Firefox pre-1.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:2289"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2441" version="1" check="at least one" comment="Mozilla Suite installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:2286"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2440" version="1" check="at least one" comment="Mozilla Suite is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1386"/>
      <state state_ref="oval:org.mitre.oval:ste:2285"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:892" version="1" check="at least one" comment="the version of Fontsub.dll is less than 5.1.2600.1762" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:668"/>
      <state state_ref="oval:org.mitre.oval:ste:801"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:891" version="1" check="at least one" comment="the version of T2embed.dll is less than 5.1.2600.1762" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:667"/>
      <state state_ref="oval:org.mitre.oval:ste:800"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2873" version="1" check="at least one" comment="File fs.auto exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1648"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2872" version="1" check="at least one" comment="File xfs exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1645"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2871" version="1" check="at least one" comment="Patch 109862-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1647"/>
      <state state_ref="oval:org.mitre.oval:ste:2689"/>
    </patch_test>
    <inetd_test id="oval:org.mitre.oval:tst:2870" version="1" check="at least one" comment="inetd.conf contains fs.auto" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1646"/>
      <state state_ref="oval:org.mitre.oval:ste:2688"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:2869" version="1" check="at least one" comment="File xfs executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1645"/>
      <state state_ref="oval:org.mitre.oval:ste:2687"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2868" version="1" check="at least one" comment="File xfs executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1645"/>
      <state state_ref="oval:org.mitre.oval:ste:2686"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2867" version="1" check="at least one" comment="File xfs executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1645"/>
      <state state_ref="oval:org.mitre.oval:ste:2685"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:893" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3835.2200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:802"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:895" version="1" check="at least one" comment="Outlook 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:670"/>
      <state state_ref="oval:org.mitre.oval:ste:804"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:894" version="1" check="at least one" comment="the version of msmapi32.dll is less than 5.5.3201.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:669"/>
      <state state_ref="oval:org.mitre.oval:ste:803"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:896" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.1.2600.1831" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:805"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:900" version="1" check="at least one" comment="Solaris Management Console Web Components (SUNWwbmc) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:674"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:899" version="1" check="at least one" comment="Patch 111313-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:673"/>
      <state state_ref="oval:org.mitre.oval:ste:807"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:898" version="1" check="at least one" comment="Patch 116807-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:672"/>
      <state state_ref="oval:org.mitre.oval:ste:806"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:897" version="1" check="at least one" comment="smcboot running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oval-def:notes>
        <oval-def:note>Solaris Management Console web interface</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:671"/>
    </process_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2877" version="1" check="at least one" comment="gtkhtml version is less than 1.1.9-0.9.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1650"/>
      <state state_ref="oval:org.mitre.oval:ste:2693"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2876" version="1" check="at least one" comment="/usr/bin/evolution is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1649"/>
      <state state_ref="oval:org.mitre.oval:ste:2692"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2875" version="1" check="at least one" comment="/usr/bin/evolution is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1649"/>
      <state state_ref="oval:org.mitre.oval:ste:2691"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2874" version="1" check="at least one" comment="/usr/bin/evolution is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1649"/>
      <state state_ref="oval:org.mitre.oval:ste:2690"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:901" version="1" check="all" comment="Netscape installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:675"/>
    </package_test>
    <file_test id="oval:org.mitre.oval:tst:902" version="1" check="at least one" comment="the version of Msdtctm.dll is less than 2001.12.4720.480" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:534"/>
      <state state_ref="oval:org.mitre.oval:ste:808"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:906" version="1" check="all" comment="HP Release B.10.20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:812"/>
    </uname_test>
    <swlist_test id="oval:org.mitre.oval:tst:905" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:678"/>
      <state state_ref="oval:org.mitre.oval:ste:811"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:904" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:677"/>
      <state state_ref="oval:org.mitre.oval:ste:810"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:903" version="1" check="at least one" comment="Patch PHNE_23948 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:676"/>
      <state state_ref="oval:org.mitre.oval:ste:809"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:910" version="1" check="at least one" comment="Patch 109023-05 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:683"/>
      <state state_ref="oval:org.mitre.oval:ste:816"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:909" version="1" check="at least one" comment="Patch 120240-01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:682"/>
      <state state_ref="oval:org.mitre.oval:ste:815"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:908" version="1" check="at least one" comment="Patch 109024-05 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:681"/>
      <state state_ref="oval:org.mitre.oval:ste:814"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:907" version="1" check="at least one" comment="Patch 120239-01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:680"/>
      <state state_ref="oval:org.mitre.oval:ste:813"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:3087" version="1" check="at least one" comment="Patch Q313829 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1756"/>
      <state state_ref="oval:org.mitre.oval:ste:2892"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2878" version="1" check="at least one" comment="the version of shell32.dll is less than 5.0.3502.4718" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:2694"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:911" version="1" check="all" comment="mshtml.dll is less than 6.0.2900.2769" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:817"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:914" version="1" check="all" comment="Samba - Usr (SUNWsmbau) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:685"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:913" version="1" check="all" comment="Patch 114684-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:506"/>
      <state state_ref="oval:org.mitre.oval:ste:818"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:912" version="1" check="all" comment="smbd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:684"/>
    </process_test>
    <patch_test id="oval:org.mitre.oval:tst:915" version="1" check="at least one" comment="Patch PHSS_34102 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:686"/>
      <state state_ref="oval:org.mitre.oval:ste:819"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:916" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.2.3790.2606" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:820"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2880" version="1" check="at least one" comment="Patch Q817606 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1651"/>
      <state state_ref="oval:org.mitre.oval:ste:2696"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2879" version="1" check="at least one" comment="The version of srv.sys is less than 4.0.1381.7214" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:384"/>
      <state state_ref="oval:org.mitre.oval:ste:2695"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:920" version="1" check="at least one" comment="CIFS-Server.CIFS-RUN with version less than A.01.11.04 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:690"/>
      <state state_ref="oval:org.mitre.oval:ste:824"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:919" version="1" check="at least one" comment="CIFS-Server.CIFS-UTIL with version less than A.01.11.04 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:689"/>
      <state state_ref="oval:org.mitre.oval:ste:823"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:918" version="1" check="at least one" comment="CIFS-Server.CIFS-ADMIN with version less than A.01.11.04 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:688"/>
      <state state_ref="oval:org.mitre.oval:ste:822"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:917" version="1" check="at least one" comment="CIFS-Server.CIFS-LIB with version less than A.01.11.04 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:687"/>
      <state state_ref="oval:org.mitre.oval:ste:821"/>
    </swlist_test>
    <registry_test id="oval:org.mitre.oval:tst:922" version="1" check="at least one" comment="Outlook 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:692"/>
      <state state_ref="oval:org.mitre.oval:ste:826"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:921" version="1" check="at least one" comment="the version of msmapi32.dll is greater than 11.0.6566.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:691"/>
      <state state_ref="oval:org.mitre.oval:ste:825"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:923" version="1" check="all" comment="mshtml.dll is less than 6.0.3790.418" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:827"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:924" version="1" check="at least one" comment="Patch PHCO_30402 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:693"/>
      <state state_ref="oval:org.mitre.oval:ste:828"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2882" version="1" check="at least one" comment="the version of mup.sys is less than 4.0.1381.7125" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1653"/>
      <state state_ref="oval:org.mitre.oval:ste:2698"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2881" version="1" check="at least one" comment="Patch Q312895 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1652"/>
      <state state_ref="oval:org.mitre.oval:ste:2697"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:925" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2900.2869" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:829"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:927" version="1" check="at least one" comment="Internet Explorer 5.01 (any patch level) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:831"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:926" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3839.2200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:830"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:933" version="1" check="at least one" comment="Patch 111313-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:673"/>
      <state state_ref="oval:org.mitre.oval:ste:837"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:932" version="1" check="at least one" comment="Patch 111314-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:697"/>
      <state state_ref="oval:org.mitre.oval:ste:836"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:931" version="1" check="at least one" comment="Patch 116807-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:672"/>
      <state state_ref="oval:org.mitre.oval:ste:835"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:930" version="1" check="at least one" comment="Patch 116808-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:696"/>
      <state state_ref="oval:org.mitre.oval:ste:834"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:929" version="1" check="at least one" comment="Patch 121308-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:695"/>
      <state state_ref="oval:org.mitre.oval:ste:833"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:928" version="1" check="at least one" comment="Patch 121309-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:694"/>
      <state state_ref="oval:org.mitre.oval:ste:832"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2959" version="1" check="at least one" comment="Patch Q314147 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1695"/>
      <state state_ref="oval:org.mitre.oval:ste:2774"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2883" version="1" check="at least one" comment="the version of snmp.exe is less than 5.0.2195.4919" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:973"/>
      <state state_ref="oval:org.mitre.oval:ste:2699"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:934" version="1" check="at least one" comment="Patch PHNE_23950 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:698"/>
      <state state_ref="oval:org.mitre.oval:ste:838"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:941" version="1" check="at least one" comment="the version of Quartz.dll is greater than or equal to 6.4.2600.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:843"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:940" version="1" check="at least one" comment="the version of Quartz.dll is less than 6.4.2600.1738" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:842"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:942" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.1.2600.2818" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:844"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:943" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.0.2195.7073" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:845"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2884" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2722.900" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2700"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:946" version="1" check="at least one" comment="OS-Core.CORE-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:707"/>
      <state state_ref="oval:org.mitre.oval:ste:848"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:945" version="1" check="at least one" comment="OS-Core.UX-CORE is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:706"/>
      <state state_ref="oval:org.mitre.oval:ste:847"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:944" version="1" check="at least one" comment="Patch PHCO_33989 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:705"/>
      <state state_ref="oval:org.mitre.oval:ste:846"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:948" version="1" check="at least one" comment="the version of httpext.dll is less than 6.0.2600.1579" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:278"/>
      <state state_ref="oval:org.mitre.oval:ste:850"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:947" version="1" check="at least one" comment="the version of httpext.dll is less than 6.0.2600.165" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:278"/>
      <state state_ref="oval:org.mitre.oval:ste:849"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:949" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.1.2600.2827 (XP,SP2)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:851"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:951" version="1" check="at least one" comment="the version of Quartz.dll is greater than or equal to 6.4.3790.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:853"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:950" version="1" check="at least one" comment="the version of Quartz.dll is less than 6.4.3790.399" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:852"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:952" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.536" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:854"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:953" version="1" check="all" comment="cdosys.dll is less than 6.1.3940.42" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:661"/>
      <state state_ref="oval:org.mitre.oval:ste:855"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2887" version="1" check="at least one" comment="Windows NT Service Pack 6a is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1655"/>
      <state state_ref="oval:org.mitre.oval:ste:2703"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2886" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:2702"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:954" version="1" check="at least one" comment="the version of winword.exe is less than 11.0.8026.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:856"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:955" version="1" check="at least one" comment="the version of wordpad.exe is less than 4.0.1381.33598" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:389"/>
      <state state_ref="oval:org.mitre.oval:ste:857"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:956" version="1" check="all" comment="msieftp.dll is less than 6.0.2800.1724" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:708"/>
      <state state_ref="oval:org.mitre.oval:ste:858"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:957" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3841.1900" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:859"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:959" version="1" check="at least one" comment="the version of ole32.dll is less than 5.2.3790.374" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:861"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:958" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.2.3790.374" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:860"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:961" version="1" check="at least one" comment="OS-Core.UX-CORE is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:711"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:960" version="1" check="at least one" comment="Patch PHCO_33219 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:710"/>
      <state state_ref="oval:org.mitre.oval:ste:862"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2378" version="2" check="at least one" comment="Excel 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1360"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2377" version="2" check="at least one" comment="the version of excel.exe is less than 10.0.6789.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2227"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3070" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2875"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3069" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2874"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3068" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2873"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3067" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2872"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3066" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2871"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3065" version="1" check="at least one" comment="Internet Explorer 5.01 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2870"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2892" version="1" check="at least one" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1659"/>
      <state state_ref="oval:org.mitre.oval:ste:2708"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2891" version="1" check="at least one" comment="the patch q290108 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1658"/>
      <state state_ref="oval:org.mitre.oval:ste:2707"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2890" version="1" check="at least one" comment="the patch q295106 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1657"/>
      <state state_ref="oval:org.mitre.oval:ste:2706"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2889" version="1" check="at least one" comment="file downloads are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:989"/>
      <state state_ref="oval:org.mitre.oval:ste:2705"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2888" version="1" check="at least one" comment="file downloads are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1656"/>
      <state state_ref="oval:org.mitre.oval:ste:2704"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:963" version="1" check="all" comment="the SUNWlzas package (for slsadmin) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:713"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:962" version="1" check="at least one" comment="Patch 121332-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:712"/>
      <state state_ref="oval:org.mitre.oval:ste:863"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:966" version="1" check="at least one" comment="IPSec.IPSEC2-KRN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:716"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:965" version="1" check="at least one" comment="IPSec.IPSEC2-KRN with version less than A.2.00.01 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:715"/>
      <state state_ref="oval:org.mitre.oval:ste:865"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:964" version="1" check="at least one" comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:714"/>
      <state state_ref="oval:org.mitre.oval:ste:864"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1441" version="1" check="at least one" comment="Patch PHNE_32606 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:983"/>
      <state state_ref="oval:org.mitre.oval:ste:1300"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:967" version="1" check="all" comment="cdosys.dll is less than 6.1.1002.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:661"/>
      <state state_ref="oval:org.mitre.oval:ste:866"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:969" version="1" check="at least one" comment="Win2K/XP/2003 service pack 1 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:868"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:968" version="1" check="at least one" comment="the version of Spoolsv.exe is less than 5.2.3790.346" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:223"/>
      <state state_ref="oval:org.mitre.oval:ste:867"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:970" version="1" check="at least one" comment="the version of winamp is less than or equal 5.12" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:718"/>
      <state state_ref="oval:org.mitre.oval:ste:869"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2893" version="1" check="at least one" comment="MTS Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1660"/>
      <state state_ref="oval:org.mitre.oval:ste:2709"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3109" version="1" check="at least one" comment="File Xsun exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1764"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3108" version="1" check="at least one" comment="Patch 108652-52 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:876"/>
      <state state_ref="oval:org.mitre.oval:ste:2912"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3107" version="1" check="at least one" comment="File Xsun SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1764"/>
      <state state_ref="oval:org.mitre.oval:ste:2911"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3106" version="1" check="at least one" comment="File Xsun SGID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1764"/>
      <state state_ref="oval:org.mitre.oval:ste:2910"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2958" version="1" check="at least one" comment="the SNMP service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1694"/>
      <state state_ref="oval:org.mitre.oval:ste:2773"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2896" version="1" check="at least one" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7064" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1662"/>
      <state state_ref="oval:org.mitre.oval:ste:2712"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2895" version="1" check="at least one" comment="File %windir%\system32\tcpcfg.dll version is less than 4.0.1381.7097" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1662"/>
      <state state_ref="oval:org.mitre.oval:ste:2711"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2894" version="1" check="at least one" comment="Patch Q265714 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1661"/>
      <state state_ref="oval:org.mitre.oval:ste:2710"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2897" version="1" check="at least one" comment="gtkhtml version is less than 1.1.9-0.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1663"/>
      <state state_ref="oval:org.mitre.oval:ste:2713"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2898" version="1" check="at least one" comment="the version of msjava.dll is less than 5.0.3810.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1446"/>
      <state state_ref="oval:org.mitre.oval:ste:2714"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2901" version="1" check="at least one" comment="gnupg version is less than 1.2.1-4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1665"/>
      <state state_ref="oval:org.mitre.oval:ste:2717"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2900" version="1" check="at least one" comment="/usr/bin/gnupg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1664"/>
      <state state_ref="oval:org.mitre.oval:ste:2716"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2899" version="1" check="at least one" comment="/usr/bin/gnupg is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1664"/>
      <state state_ref="oval:org.mitre.oval:ste:2715"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:972" version="1" check="at least one" comment="the patch kb890175 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:720"/>
      <state state_ref="oval:org.mitre.oval:ste:871"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:971" version="1" check="at least one" comment="the version of hhctrl.ocx is less than 5.2.3790.233" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:531"/>
      <state state_ref="oval:org.mitre.oval:ste:870"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:974" version="1" check="all" comment="FreeRADIUS rpm older than 1.0.1-1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:722"/>
      <state state_ref="oval:org.mitre.oval:ste:873"/>
    </rpminfo_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:973" version="1" check="all" comment="radiusd is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:721"/>
      <state state_ref="oval:org.mitre.oval:ste:872"/>
    </inetlisteningservers_test>
    <swlist_test id="oval:org.mitre.oval:tst:2388" version="1" check="at least one" comment="hpuxwsAPACHE is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1365"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2387" version="1" check="at least one" comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1364"/>
      <state state_ref="oval:org.mitre.oval:ste:2236"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:976" version="1" check="at least one" comment="the version of mstask.dll is less than 4.71.1979.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:379"/>
      <state state_ref="oval:org.mitre.oval:ste:875"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:975" version="1" check="at least one" comment="Patch IE-KB841873-WindowsNT4sp6-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:723"/>
      <state state_ref="oval:org.mitre.oval:ste:874"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1469" version="1" check="at least one" comment="Win2K/XP/2003 service pack 6 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:1327"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2907" version="1" check="at least one" comment="the version of jscript.dll is less than 5.1.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:2723"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2906" version="1" check="at least one" comment="the version of jscript.dll is less than 5.5.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:2722"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2905" version="1" check="at least one" comment="the version of jscript.dll is less than 5.6.0.8513" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:2721"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2904" version="1" check="at least one" comment="the patch js56nen.exe (5.6.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1666"/>
      <state state_ref="oval:org.mitre.oval:ste:2720"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2903" version="1" check="at least one" comment="the patch js56nen.exe (5.1.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1666"/>
      <state state_ref="oval:org.mitre.oval:ste:2719"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2902" version="1" check="at least one" comment="the patch js56nen.exe (5.5.0.8513 version) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1666"/>
      <state state_ref="oval:org.mitre.oval:ste:2718"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2446" version="1" check="at least one" comment="The version of Firefox.exe is greater than or equal to 1.8.20060.11112" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:561"/>
      <state state_ref="oval:org.mitre.oval:ste:2291"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:978" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.259" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:877"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:977" version="1" check="at least one" comment="the patch kb834707(wildcard*) is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:724"/>
      <state state_ref="oval:org.mitre.oval:ste:876"/>
    </registry_test>
    <swlist_test id="oval:org.mitre.oval:tst:981" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:727"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:980" version="1" check="at least one" comment="Patch PHNE_34543 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:726"/>
      <state state_ref="oval:org.mitre.oval:ste:879"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:979" version="1" check="at least one" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:725"/>
      <state state_ref="oval:org.mitre.oval:ste:878"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:982" version="1" check="at least one" comment="the version of cryptdlg.dll is less than 5.0.1558.6608" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:728"/>
      <state state_ref="oval:org.mitre.oval:ste:880"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:983" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8930" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:881"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2836" version="1" check="at least one" comment="Word 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1626"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:985" version="1" check="at least one" comment="the version of httpext.dll is less than 5.0.2195.6958" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:278"/>
      <state state_ref="oval:org.mitre.oval:ste:883"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:984" version="1" check="at least one" comment="the patch KB824151 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:729"/>
      <state state_ref="oval:org.mitre.oval:ste:882"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2953" version="1" check="at least one" comment="WebDav is disabled(for iis 5.0)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1691"/>
      <state state_ref="oval:org.mitre.oval:ste:2768"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2911" version="1" check="at least one" comment="ghostscript version is less than 7.05-32.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1668"/>
      <state state_ref="oval:org.mitre.oval:ste:2727"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2910" version="1" check="at least one" comment="/usr/bin/gs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1667"/>
      <state state_ref="oval:org.mitre.oval:ste:2726"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2909" version="1" check="at least one" comment="/usr/bin/gs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1667"/>
      <state state_ref="oval:org.mitre.oval:ste:2725"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2908" version="1" check="at least one" comment="/usr/bin/gs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1667"/>
      <state state_ref="oval:org.mitre.oval:ste:2724"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:986" version="1" check="all" comment="umpnpmgr.dll is less than 5.1.2600.1734" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:224"/>
      <state state_ref="oval:org.mitre.oval:ste:884"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2664" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3831.1800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2488"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:987" version="1" check="at least one" comment="the version of msadco.dll is less than 2.80.1062.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:885"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:988" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7268" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:886"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2622" version="1" check="at least one" comment="the patch kb885835is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1495"/>
      <state state_ref="oval:org.mitre.oval:ste:2451"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2408" version="2" check="at least one" comment="this is an NT Server (stand-alone)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1550"/>
      <state state_ref="oval:org.mitre.oval:ste:2256"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3096" version="1" check="at least one" comment="the version of w3svc.dll is less than 4.2.775.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:496"/>
      <state state_ref="oval:org.mitre.oval:ste:2901"/>
    </file_test>
    <metabase_test id="oval:org.mitre.oval:tst:3092" version="1" check="at least one" comment="asp.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1757"/>
      <state state_ref="oval:org.mitre.oval:ste:2897"/>
    </metabase_test>
    <file_test id="oval:org.mitre.oval:tst:990" version="1" check="at least one" comment="the version of Mdbmsg.dll greater than or equal 5.0.1460.9 (Exchange Server 5.0,SP2 is installed)." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:730"/>
      <state state_ref="oval:org.mitre.oval:ste:888"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:989" version="1" check="at least one" comment="the version of Mdbmsg.dll is less than 5.0.1462.22" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:730"/>
      <state state_ref="oval:org.mitre.oval:ste:887"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:992" version="1" check="at least one" comment="Exchange Server 2000,SP3 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:732"/>
      <state state_ref="oval:org.mitre.oval:ste:890"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:991" version="1" check="all" comment="mdbmsg.dll is less than 6.0.6618.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:731"/>
      <state state_ref="oval:org.mitre.oval:ste:889"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:993" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.2.3790.468 (S03-Gold)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:563"/>
      <state state_ref="oval:org.mitre.oval:ste:891"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2912" version="1" check="at least one" comment="Patch 108376-30 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1460"/>
      <state state_ref="oval:org.mitre.oval:ste:2728"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:994" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3825.700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:892"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:999" version="1" check="at least one" comment=".wvx EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:737"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:998" version="1" check="at least one" comment=".wpl EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:736"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:997" version="1" check="at least one" comment=".wmx EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:735"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:996" version="1" check="at least one" comment=".wms EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:734"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:995" version="1" check="at least one" comment=".wmz EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:733"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1004" version="1" check="at least one" comment="Windows Media Player 9.0 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:593"/>
      <state state_ref="oval:org.mitre.oval:ste:895"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1003" version="1" check="at least one" comment="the version of wmp.dll is les than 9.0.0.3250" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:527"/>
      <state state_ref="oval:org.mitre.oval:ste:894"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1002" version="1" check="at least one" comment="The patch KB885492 is installed on Windows XP" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:740"/>
      <state state_ref="oval:org.mitre.oval:ste:893"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1001" version="1" check="at least one" comment=".asx EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:739"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1000" version="1" check="at least one" comment=".wax EXISTS" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:738"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2807" version="1" check="at least one" comment="the patch kb891711 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1606"/>
      <state state_ref="oval:org.mitre.oval:ste:2627"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1005" version="1" check="at least one" comment="the version of user32.dll is less than 5.1.2600.1617" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:390"/>
      <state state_ref="oval:org.mitre.oval:ste:896"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3095" version="1" check="at least one" comment="Patch Q319733 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1760"/>
      <state state_ref="oval:org.mitre.oval:ste:2900"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:3080" version="1" check="at least one" comment="the version of w3svc.dll is less than 5.0.2195.5269" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:496"/>
      <state state_ref="oval:org.mitre.oval:ste:2885"/>
    </file_test>
    <metabase_test id="oval:org.mitre.oval:tst:3057" version="1" check="at least one" comment="ism.dll mapping exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1748"/>
      <state state_ref="oval:org.mitre.oval:ste:2862"/>
    </metabase_test>
    <file_test check="all" comment="The version of Hhctrl.ocx is less than 5.2.3790.558." id="oval:org.mitre.oval:tst:44" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:531"/>
      <state state_ref="oval:org.mitre.oval:ste:110"/>
    </file_test>
    <file_test check="all" comment="The version of Hhctrl.ocx is less than 5.2.3790.2744." id="oval:org.mitre.oval:tst:15" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:531"/>
      <state state_ref="oval:org.mitre.oval:ste:130"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1006" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2802" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:897"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1007" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.2.3790.366" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:898"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1008" version="1" check="at least one" comment="the version of Msdtctm.dll is less than 2001.12.4414.65" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:534"/>
      <state state_ref="oval:org.mitre.oval:ste:899"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1010" version="1" check="at least one" comment="the patch kb889293 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:742"/>
      <state state_ref="oval:org.mitre.oval:ste:901"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1009" version="1" check="at least one" comment="the patch kb889293 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:741"/>
      <state state_ref="oval:org.mitre.oval:ste:900"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2332" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1543" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2184"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1011" version="1" check="all" comment="netman.dll is less than 5.0.2195.7061" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:658"/>
      <state state_ref="oval:org.mitre.oval:ste:902"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2353" version="1" check="at least one" comment="the patch KB893066 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1348"/>
      <state state_ref="oval:org.mitre.oval:ste:2203"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1012" version="1" check="at least one" comment="the version of Tcpip.sys is less than 5.0.2195.7035" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:588"/>
      <state state_ref="oval:org.mitre.oval:ste:903"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:1015" version="1" check="all" comment="HP Release B.11.22" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:905"/>
    </uname_test>
    <swlist_test id="oval:org.mitre.oval:tst:1014" version="1" check="at least one" comment="Mozilla is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:744"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:1013" version="1" check="at least one" comment="Mozilla v1.7.12 (1.7.12.0.00) or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:743"/>
      <state state_ref="oval:org.mitre.oval:ste:904"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:1016" version="1" check="all" comment="msieftp.dll is less than 6.0.3790.383" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:708"/>
      <state state_ref="oval:org.mitre.oval:ste:906"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1017" version="1" check="at least one" comment="the version of mscms.dll is less than 5.0.2195.7054" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:745"/>
      <state state_ref="oval:org.mitre.oval:ste:907"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1345" version="1" check="at least one" comment="Windows 98 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:629"/>
      <state state_ref="oval:org.mitre.oval:ste:1207"/>
    </registry_test>
    <uname_test id="oval:org.mitre.oval:tst:2512" version="1" check="all" comment="HP Release B.11.00" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2352"/>
    </uname_test>
    <swlist_test id="oval:org.mitre.oval:tst:2376" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1359"/>
      <state state_ref="oval:org.mitre.oval:ste:2226"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:2375" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1358"/>
      <state state_ref="oval:org.mitre.oval:ste:2225"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1018" version="1" check="at least one" comment="Patch PHNE_23949 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:746"/>
      <state state_ref="oval:org.mitre.oval:ste:908"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2737" version="1" check="at least one" comment="the patch KB890859 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1572"/>
      <state state_ref="oval:org.mitre.oval:ste:2558"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1025" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.2.3790.280" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:914"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1027" version="1" check="at least one" comment="the version of Quartz.dll is greater than or equal to 6.1.9.726" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:916"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1026" version="1" check="at least one" comment="the version of Quartz.dll is less than 6.1.9.732" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:915"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1029" version="1" check="at least one" comment="Mozilla Firefox version 1.0.7 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:753"/>
      <state state_ref="oval:org.mitre.oval:ste:918"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1028" version="1" check="at least one" comment="Firefox version 1.0.7 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:917"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:1030" version="1" check="at least one" comment="Patch PHNE_34306 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:754"/>
      <state state_ref="oval:org.mitre.oval:ste:919"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2885" version="1" check="at least one" comment="the patch Q811493 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1654"/>
      <state state_ref="oval:org.mitre.oval:ste:2701"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1031" version="1" check="at least one" comment="The version of Ntoskrnl.exe is less than 5.1.2600.1151" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:335"/>
      <state state_ref="oval:org.mitre.oval:ste:920"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2436" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.2.3790.419" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:2281"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:1033" version="1" check="at least one" comment="Secure_Shell.SECURE_SHELL is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:756"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:1032" version="1" check="at least one" comment="Secure_Shell.SECURE_SHELL with version less than A.04.20.005 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:755"/>
      <state state_ref="oval:org.mitre.oval:ste:921"/>
    </swlist_test>
    <file_test id="oval:org.mitre.oval:tst:3003" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2723.2500" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2814"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2482" version="1" check="all" comment="mozilla RPM is earlier than 37:1.7.10-1.1.3.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <oval-def:notes>
        <oval-def:note>Multiple RPMs were updated in this release, but all but mozilla-nspr have mozilla-with-their-same-version as an installation dependency.  So, if mozilla is up to date, mozilla-chat, mozilla-devel, ... , mozilla-js-debugger are all up to date.  Mozilla itself requires that mozilla-nspr and mozilla-nss be installed with the same version as itself.  This closes the loop -- if mozilla is up to date, so are the other mozilla-FOO RPMs.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:1413"/>
      <state state_ref="oval:org.mitre.oval:ste:2326"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:1035" version="1" check="at least one" comment="Windows Media Player 8 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:757"/>
      <state state_ref="oval:org.mitre.oval:ste:923"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1034" version="1" check="at least one" comment="the version of Wmpui.dll is less than 8.0.0.4495" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:639"/>
      <state state_ref="oval:org.mitre.oval:ste:922"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2391" version="1" check="at least one" comment="the patch kb896426 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1367"/>
      <state state_ref="oval:org.mitre.oval:ste:2239"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1036" version="1" check="at least one" comment="the version of webclnt.dll is less than 5.2.3790.1673" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:628"/>
      <state state_ref="oval:org.mitre.oval:ste:924"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1037" version="1" check="all" comment="netman.dll is less than 5.1.2600.1733" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:658"/>
      <state state_ref="oval:org.mitre.oval:ste:925"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2568" version="1" check="at least one" comment="the version of ole32.dll is less than 5.0.2195.7059" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:2401"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2567" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.0.2195.7059" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:2400"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1038" version="1" check="all" comment="netman.dll is less than 5.2.3790.396" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:658"/>
      <state state_ref="oval:org.mitre.oval:ste:926"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:1040" version="1" check="at least one" comment="VirusVault is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:759"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1039" version="1" check="at least one" comment="Patch PHSS_34123 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:758"/>
      <state state_ref="oval:org.mitre.oval:ste:927"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1042" version="1" check="all" comment="gedit RPM earlier than 1:2.2.2-4rhel3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:761"/>
      <state state_ref="oval:org.mitre.oval:ste:929"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1041" version="1" check="all" comment="/usr/bin/gedit is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:760"/>
      <state state_ref="oval:org.mitre.oval:ste:928"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1043" version="1" check="all" comment="umpnpmgr.dll is less than 5.0.2195.7069" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:224"/>
      <state state_ref="oval:org.mitre.oval:ste:930"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1046" version="1" check="all" comment="sudo RPM earlier than 0:1.6.7p5-1.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:764"/>
      <state state_ref="oval:org.mitre.oval:ste:932"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1045" version="1" check="at least one" comment="/etc/sudoers exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:763"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1044" version="1" check="all" comment="/usr/bin/sudo is executable by everyone" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:762"/>
      <state state_ref="oval:org.mitre.oval:ste:931"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1047" version="1" check="at least one" comment="the version of wordpad.exe is less than 5.0.2195.6991" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:389"/>
      <state state_ref="oval:org.mitre.oval:ste:933"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3053" version="1" check="at least one" comment="File cachefsd exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1743"/>
    </file_test>
    <inetd_test id="oval:org.mitre.oval:tst:3049" version="1" check="at least one" comment="inetd.conf contains cachefsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1744"/>
      <state state_ref="oval:org.mitre.oval:ste:2855"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:3048" version="1" check="at least one" comment="File cachefsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1743"/>
      <state state_ref="oval:org.mitre.oval:ste:2854"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3047" version="1" check="at least one" comment="File cachefsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1743"/>
      <state state_ref="oval:org.mitre.oval:ste:2853"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3046" version="1" check="at least one" comment="File cachefsd executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1743"/>
      <state state_ref="oval:org.mitre.oval:ste:2852"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3024" version="1" check="at least one" comment="Patch 108800-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1731"/>
      <state state_ref="oval:org.mitre.oval:ste:2832"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:2359" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3828.2700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2209"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:2341" version="1" check="at least one" comment="Patch PHSS_34169 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1341"/>
      <state state_ref="oval:org.mitre.oval:ste:2192"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1062" version="1" check="at least one" comment="VirtualvaultTS A.04.70 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:779"/>
      <state state_ref="oval:org.mitre.oval:ste:948"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:1061" version="1" check="at least one" comment="VirtualvaultWS A.04.70 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:778"/>
      <state state_ref="oval:org.mitre.oval:ste:947"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1060" version="1" check="at least one" comment="Patch PHSS_34121 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:777"/>
      <state state_ref="oval:org.mitre.oval:ste:946"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1059" version="1" check="at least one" comment="VirtualvaultTS A.04.60 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:776"/>
      <state state_ref="oval:org.mitre.oval:ste:945"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1058" version="1" check="at least one" comment="Patch PHSS_34170 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:775"/>
      <state state_ref="oval:org.mitre.oval:ste:944"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1057" version="1" check="at least one" comment="VirtualvaultWS A.04.60 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:774"/>
      <state state_ref="oval:org.mitre.oval:ste:943"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1056" version="1" check="at least one" comment="Patch PHSS_34120 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:773"/>
      <state state_ref="oval:org.mitre.oval:ste:942"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1055" version="1" check="at least one" comment="VirtualvaultTS A.04.50 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:772"/>
      <state state_ref="oval:org.mitre.oval:ste:941"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1054" version="1" check="at least one" comment="Patch PHSS_34171 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:771"/>
      <state state_ref="oval:org.mitre.oval:ste:940"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1053" version="1" check="at least one" comment="VirtualvaultWS A.04.50 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:770"/>
      <state state_ref="oval:org.mitre.oval:ste:939"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1052" version="1" check="at least one" comment="Patch PHSS_34119 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:769"/>
      <state state_ref="oval:org.mitre.oval:ste:938"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1051" version="1" check="at least one" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:768"/>
      <state state_ref="oval:org.mitre.oval:ste:937"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1050" version="1" check="at least one" comment="Patch PHSS_34203 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:767"/>
      <state state_ref="oval:org.mitre.oval:ste:936"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:1049" version="1" check="at least one" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:766"/>
      <state state_ref="oval:org.mitre.oval:ste:935"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1048" version="1" check="at least one" comment="Patch PHSS_34204 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:765"/>
      <state state_ref="oval:org.mitre.oval:ste:934"/>
    </patch_test>
    <registry_test check="at least one" comment="Word 2003 is installed" id="oval:org.mitre.oval:tst:2649" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1518"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2648" version="2" check="at least one" comment="the version of wordview.exe is less than 11.0.6506.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1517"/>
      <state state_ref="oval:org.mitre.oval:ste:2474"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1064" version="1" check="at least one" comment="the version of Quartz.dll is greater than or equal to 6.5.2600.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:950"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1063" version="1" check="at least one" comment="the version of Quartz.dll is less than 6.5.2600.2749" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:949"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1066" version="1" check="at least one" comment="Windows Media Player 7.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:780"/>
      <state state_ref="oval:org.mitre.oval:ste:952"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1065" version="1" check="at least one" comment="the version of wmpui.dll is less than 7.10.0.3076" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:558"/>
      <state state_ref="oval:org.mitre.oval:ste:951"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2918" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1264" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2734"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2915" version="1" check="at least one" comment=".hta applications are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1670"/>
      <state state_ref="oval:org.mitre.oval:ste:2731"/>
    </registry_test>
    <package_test id="oval:org.mitre.oval:tst:1070" version="1" check="all" comment="Mozilla (SUNWmoznav) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:784"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:1069" version="1" check="all" comment="Mozilla Mail (SUNWmozmail) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:783"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:1068" version="1" check="all" comment="Patch 117765-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:782"/>
      <state state_ref="oval:org.mitre.oval:ste:954"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1067" version="1" check="all" comment="Patch 117767-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:781"/>
      <state state_ref="oval:org.mitre.oval:ste:953"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:1073" version="1" check="at least one" comment="Microsoft Interactive Training is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <oval-def:notes>
        <oval-def:note>As stated in the iDefense security advisory, if this key exists and contains a value, then the system has Interactive Training installed, and it will process .cbo files.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:787"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1072" version="1" check="at least one" comment="the version of Orun32.exe is less than 3.5.0.117" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:786"/>
      <state state_ref="oval:org.mitre.oval:ste:955"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1071" version="1" check="at least one" comment="the patch kb898458  is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:785"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1074" version="1" check="at least one" comment="the version of Msdtctm.dll is less than 2000.2.3535.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:534"/>
      <state state_ref="oval:org.mitre.oval:ste:956"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2395" version="1" check="at least one" comment="the version of webclnt.dll is less than 5.2.3790.2591 (64-bit,SP1)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:628"/>
      <state state_ref="oval:org.mitre.oval:ste:2243"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2801" version="1" check="at least one" comment="Internet Explorer 6  for Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2621"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2335" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.373" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2187"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2334" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2491" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2186"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2414" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.2.3790.2542" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:2262"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1075" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.0.2195.7057" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:957"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:1077" version="1" check="all" comment="HP Release B.10.24" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:959"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:1076" version="1" check="at least one" comment="Patch PHNE_24394 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:788"/>
      <state state_ref="oval:org.mitre.oval:ste:958"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:1078" version="1" check="all" comment="nwwks.dll is less than 5.1.2600.2736" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:652"/>
      <state state_ref="oval:org.mitre.oval:ste:960"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2977" version="1" check="at least one" comment="SQL Server 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1470"/>
      <state state_ref="oval:org.mitre.oval:ste:2791"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2926" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.608.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:2742"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2925" version="1" check="at least one" comment="the version of odsole70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:903"/>
      <state state_ref="oval:org.mitre.oval:ste:2741"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2924" version="1" check="at least one" comment="the version of xpqueue.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:902"/>
      <state state_ref="oval:org.mitre.oval:ste:2740"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2923" version="1" check="at least one" comment="the version of xprepl.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:901"/>
      <state state_ref="oval:org.mitre.oval:ste:2739"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2922" version="1" check="at least one" comment="the version of xplog70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:900"/>
      <state state_ref="oval:org.mitre.oval:ste:2738"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2921" version="1" check="at least one" comment="the version of xpweb70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:899"/>
      <state state_ref="oval:org.mitre.oval:ste:2737"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2920" version="1" check="at least one" comment="the version of xpstar.dll is less than 2000.80.628.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:898"/>
      <state state_ref="oval:org.mitre.oval:ste:2736"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2365" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1505 (RTMGDR)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2215"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2364" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1506 (RTMQFE)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2214"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1079" version="1" check="at least one" comment="the version of msadco.dll is less than 2.81.1124.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:961"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2913" version="1" check="at least one" comment="DCOM is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1669"/>
      <state state_ref="oval:org.mitre.oval:ste:2729"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1080" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.2.3790.76" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:962"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1081" version="1" check="all" comment="cdoex.dll is less than 6.0.6617.86" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:789"/>
      <state state_ref="oval:org.mitre.oval:ste:963"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2931" version="1" check="at least one" comment="File kcms_server exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1672"/>
    </file_test>
    <inetd_test id="oval:org.mitre.oval:tst:2930" version="1" check="at least one" comment="inetd.conf contains kcms_server" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1673"/>
      <state state_ref="oval:org.mitre.oval:ste:2746"/>
    </inetd_test>
    <file_test id="oval:org.mitre.oval:tst:2929" version="1" check="at least one" comment="File kcms_server executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1672"/>
      <state state_ref="oval:org.mitre.oval:ste:2745"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2928" version="1" check="at least one" comment="File kcms_server executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1672"/>
      <state state_ref="oval:org.mitre.oval:ste:2744"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2927" version="1" check="at least one" comment="File kcms_server executable and SUID or SGID" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1672"/>
      <state state_ref="oval:org.mitre.oval:ste:2743"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3122" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4913.1100" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2925"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3121" version="1" check="at least one" comment="the patch q316059 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1776"/>
      <state state_ref="oval:org.mitre.oval:ste:2924"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3120" version="1" check="at least one" comment="the patch q319282 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1775"/>
      <state state_ref="oval:org.mitre.oval:ste:2923"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1083" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3539.2400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:965"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1082" version="1" check="at least one" comment="the patch kb890923  is installed (Win2K SP3  Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:790"/>
      <state state_ref="oval:org.mitre.oval:ste:964"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1085" version="1" check="all" comment="libgd RPM is earlier than 0:1.8.4-12.3.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:792"/>
      <state state_ref="oval:org.mitre.oval:ste:967"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1084" version="1" check="all" comment="libgd-devel RPM is earlier than 0:1.8.4-12.3.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:791"/>
      <state state_ref="oval:org.mitre.oval:ste:966"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2425" version="2" check="at least one" comment="the version of agentdpv.dll is less than 2.0.0.3423" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1000"/>
      <state state_ref="oval:org.mitre.oval:ste:2272"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2424" version="1" check="at least one" comment="the patch kb890046 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1380"/>
      <state state_ref="oval:org.mitre.oval:ste:2271"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1476" version="2" check="at least one" comment="the version of agentdpv.dll is less than 5.2.3790.1241" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1000"/>
      <state state_ref="oval:org.mitre.oval:ste:1334"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1086" version="1" check="all" comment="shell32.dll is less than 5.0.3900.7071" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:968"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1087" version="1" check="at least one" comment="the version of shell32.dll is less than 5.0.3900.7078" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:969"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2641" version="1" check="at least one" comment="Word 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1510"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1088" version="1" check="at least one" comment="the version of winword.exe is less than 10.00.6764.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:970"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2443" version="1" check="at least one" comment="Mozilla Firefox version 1.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1387"/>
      <state state_ref="oval:org.mitre.oval:ste:2288"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2442" version="1" check="at least one" comment="Firefox version 1.5 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:2287"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1096" version="1" check="at least one" comment="The version of Firefox.exe is greater than or equal to 1.8.20060.30804 (v1.5.0.2)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:561"/>
      <state state_ref="oval:org.mitre.oval:ste:978"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1095" version="1" check="at least one" comment="Mozilla Firefox version 1.5.0.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:798"/>
      <state state_ref="oval:org.mitre.oval:ste:977"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1094" version="1" check="at least one" comment="Firefox version 1.5.0.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:976"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1093" version="1" check="at least one" comment="Thunderbird version 1.5 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:975"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1092" version="1" check="at least one" comment="Mozilla Thunderbird version 1.5 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:797"/>
      <state state_ref="oval:org.mitre.oval:ste:974"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1091" version="1" check="at least one" comment="The version of thunderbird.exe is greater than or equal to 1.8.20060.30803 (v1.5.0.2)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:795"/>
      <state state_ref="oval:org.mitre.oval:ste:973"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1090" version="1" check="at least one" comment="SeaMonkey version 1.0 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:794"/>
      <state state_ref="oval:org.mitre.oval:ste:972"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1089" version="1" check="at least one" comment="SeaMonkey version 1.0 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:793"/>
      <state state_ref="oval:org.mitre.oval:ste:971"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1406" version="1" check="at least one" comment="the version of itss.dll is less than 5.2.3790.185" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:966"/>
      <state state_ref="oval:org.mitre.oval:ste:1265"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1405" version="1" check="at least one" comment="the patch kb840315 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:965"/>
      <state state_ref="oval:org.mitre.oval:ste:1264"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1404" version="1" check="at least one" comment="HTML Help is registered" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:964"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1098" version="1" check="at least one" comment="the version of Fontsub.dll is less than 5.2.3790.2549" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:668"/>
      <state state_ref="oval:org.mitre.oval:ste:980"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1097" version="1" check="at least one" comment="the version of T2embed.dll is less than 5.2.3790.2549" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:667"/>
      <state state_ref="oval:org.mitre.oval:ste:979"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1099" version="1" check="at least one" comment="the version of ole32.dll is less than 5.1.2600.2595" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:981"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2933" version="1" check="at least one" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:384"/>
      <state state_ref="oval:org.mitre.oval:ste:2748"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2932" version="1" check="at least one" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1674"/>
      <state state_ref="oval:org.mitre.oval:ste:2747"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1100" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.507" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:982"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3779" version="1" check="at least one" comment="Patch PHNE_33159 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2756"/>
      <state state_ref="oval:org.mitre.oval:ste:3712"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3704" version="1" check="all" comment="HP Release B.11.11" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3389"/>
    </uname_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1102" version="1" check="all" comment="libxml RPM is earlier than 1:1.8.17-9.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:800"/>
      <state state_ref="oval:org.mitre.oval:ste:984"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1101" version="1" check="all" comment="libxml-devel RPM is earlier than 1:1.8.17-9.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:799"/>
      <state state_ref="oval:org.mitre.oval:ste:983"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:2935" version="1" check="at least one" comment="ISA Server 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1676"/>
      <state state_ref="oval:org.mitre.oval:ste:2750"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2934" version="1" check="at least one" comment="ISA2000-KB816456-x86.exe" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1675"/>
      <state state_ref="oval:org.mitre.oval:ste:2749"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2666" version="1" check="all" comment="/usr/bin/gzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1528"/>
      <state state_ref="oval:org.mitre.oval:ste:2490"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2665" version="1" check="all" comment="/usr/bin/gunzip is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1527"/>
      <state state_ref="oval:org.mitre.oval:ste:2489"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2421" version="1" check="at least one" comment="Word for Windows 6.0 Converter is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1378"/>
      <state state_ref="oval:org.mitre.oval:ste:2268"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1104" version="1" check="at least one" comment="the patch kb885836 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:802"/>
      <state state_ref="oval:org.mitre.oval:ste:986"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1103" version="1" check="at least one" comment="the version of mswrd632.wpc is less than 2004.10.25.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:801"/>
      <state state_ref="oval:org.mitre.oval:ste:985"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1106" version="1" check="at least one" comment="Outlook 2002 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:804"/>
      <state state_ref="oval:org.mitre.oval:ste:988"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1105" version="1" check="at least one" comment="the version of msmapi32.dll is less than 10.0.6772.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:803"/>
      <state state_ref="oval:org.mitre.oval:ste:987"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3960" version="1" check="at least one" comment="Patch 118844-14 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1890"/>
      <state state_ref="oval:org.mitre.oval:ste:3645"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3912" version="1" check="at least one" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3443"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:3680" version="1" check="at least one" comment="Solaris 10 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3597"/>
    </uname_test>
    <registry_test id="oval:org.mitre.oval:tst:1108" version="1" check="at least one" comment="Exchange Server 2003,SP1 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:732"/>
      <state state_ref="oval:org.mitre.oval:ste:990"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1107" version="1" check="all" comment="mdbmsg.dll is less than 6.5.7233.69" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:731"/>
      <state state_ref="oval:org.mitre.oval:ste:989"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3771" version="1" check="at least one" comment="Patch 119450-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2245"/>
      <state state_ref="oval:org.mitre.oval:ste:3724"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:3644" version="1" check="at least one" comment="Patch 119449-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:2729"/>
      <state state_ref="oval:org.mitre.oval:ste:3291"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3437" version="1" check="at least one" comment="Solaris 8 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3700"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:3237" version="1" check="at least one" comment="sparc architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3478"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:3172" version="1" check="at least one" comment="Solaris 9 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3891"/>
    </uname_test>
    <registry_test id="oval:org.mitre.oval:tst:1485" version="1" check="at least one" comment="the patch KB873333 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1008"/>
      <state state_ref="oval:org.mitre.oval:ste:1342"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1109" version="1" check="at least one" comment="the version of ole32.dll is less than 5.0.2195.7021" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:991"/>
    </file_test>
    <registry_test check="at least one" comment="Excel 2000 is installed" id="oval:org.mitre.oval:tst:2485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1415"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1110" version="2" check="at least one" comment="the version of excel.exe is less than 9.0.0.8938" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:992"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1114" version="1" check="all" comment="mshtml.dll is less than 6.0.3790.2541" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:995"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2385" version="1" check="all" comment="/usr/bin/bzip2 is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1362"/>
      <state state_ref="oval:org.mitre.oval:ste:2234"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1116" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.1.2600.1755" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:997"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1115" version="1" check="at least one" comment="the version of Mf3216.dll is less than 5.1.2600.1331" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:807"/>
      <state state_ref="oval:org.mitre.oval:ste:996"/>
    </file_test>
    <swlist_test id="oval:org.mitre.oval:tst:1119" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:810"/>
      <state state_ref="oval:org.mitre.oval:ste:1000"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:1118" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:809"/>
      <state state_ref="oval:org.mitre.oval:ste:999"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:1117" version="1" check="at least one" comment="Patch PHNE_33791 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:808"/>
      <state state_ref="oval:org.mitre.oval:ste:998"/>
    </patch_test>
    <file_test check="all" comment="The version of Hlink.dll is less than 5.2.3790.2748." id="oval:org.mitre.oval:tst:180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:391"/>
      <state state_ref="oval:org.mitre.oval:ste:167"/>
    </file_test>
    <file_test check="all" comment="The version of Hlink.dll is less than 5.2.3790.560." id="oval:org.mitre.oval:tst:114" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:391"/>
      <state state_ref="oval:org.mitre.oval:ste:18"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1123" version="1" check="at least one" comment="the version of Quartz.dll is greater than or equal to 6.5.3790.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:1004"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1122" version="1" check="at least one" comment="the version of Quartz.dll is less than 6.5.3790.2519" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:1003"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1121" version="1" check="at least one" comment="the version of Quartz.dll is less than 6.3.1.889" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:704"/>
      <state state_ref="oval:org.mitre.oval:ste:1002"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1120" version="1" check="at least one" comment="DirectX 9.x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1001"/>
    </registry_test>
    <uname_test id="oval:org.mitre.oval:tst:2514" version="1" check="all" comment="HP Release B.11.11" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2354"/>
    </uname_test>
    <swlist_test id="oval:org.mitre.oval:tst:1124" version="1" check="at least one" comment="WUFTP-26.INETSVCS-FTP with version less than B.11.00.01.004 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:811"/>
      <state state_ref="oval:org.mitre.oval:ste:1005"/>
    </swlist_test>
    <registry_test id="oval:org.mitre.oval:tst:2569" version="1" check="at least one" comment="Win2K/XP/2003 service pack 4 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2402"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1125" version="1" check="all" comment="msieftp.dll is less than 5.50.4956.500" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:708"/>
      <state state_ref="oval:org.mitre.oval:ste:1006"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2611" version="1" check="at least one" comment="ISA Server 2000 SP2 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1487"/>
      <state state_ref="oval:org.mitre.oval:ste:2440"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2610" version="1" check="at least one" comment="the version of w3proxy.exe is less than 3.0.1200.430" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1485"/>
      <state state_ref="oval:org.mitre.oval:ste:2439"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2609" version="1" check="at least one" comment="the patch KB899753 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1484"/>
      <state state_ref="oval:org.mitre.oval:ste:2438"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1126" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2666" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1007"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2745" version="1" check="all" comment="the version of srv.sys is less than 5.2.3790.2437" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:2566"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2743" version="1" check="at least one" comment="the patch KB896422 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1575"/>
      <state state_ref="oval:org.mitre.oval:ste:2564"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1128" version="1" check="all" comment="the version of srv.sys is less than 5.1.2600.1683" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:1009"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1127" version="1" check="all" comment="the version of srv.sys is less than 5.1.2600.2673" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:812"/>
      <state state_ref="oval:org.mitre.oval:ste:1008"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2418" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1515 (RTMGDR)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2266"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2417" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1516 (RTMQFE)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2265"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1129" version="1" check="at least one" comment="the patch kb896727 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:813"/>
      <state state_ref="oval:org.mitre.oval:ste:1010"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:2994" version="1" check="at least one" comment="Patch 107709-19 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:868"/>
      <state state_ref="oval:org.mitre.oval:ste:2806"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1131" version="1" check="all" comment="telnet RPM earlier than 1:0.17-20.EL3.3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:815"/>
      <state state_ref="oval:org.mitre.oval:ste:1012"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1130" version="1" check="all" comment="/usr/bin/telnet is executable by any user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:814"/>
      <state state_ref="oval:org.mitre.oval:ste:1011"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1132" version="1" check="all" comment="the version of mrxsmb.sys is less than 5.2.3790.2697" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:326"/>
      <state state_ref="oval:org.mitre.oval:ste:1013"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2539" version="1" check="at least one" comment="the version of ole32.dll is less than 5.2.3790.2492" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:2374"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2538" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.2.3790.2492" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:2373"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1134" version="1" check="at least one" comment="the version of ole32.dll is less than 5.1.2600.2726" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:1015"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1133" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.1.2600.2726" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:1014"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2802" version="1" check="at least one" comment="the patch kb832894 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1604"/>
      <state state_ref="oval:org.mitre.oval:ste:2622"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2765" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1458" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2586"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2503" version="1" check="all" comment="the version of telnet.exe is less than 5.2.3790.2442" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:816"/>
      <state state_ref="oval:org.mitre.oval:ste:2344"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2502" version="1" check="at least one" comment="the patch KB896428 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1425"/>
      <state state_ref="oval:org.mitre.oval:ste:2343"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1135" version="1" check="all" comment="the version of telnet.exe is less than 5.1.2600.1684" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:816"/>
      <state state_ref="oval:org.mitre.oval:ste:1016"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1136" version="1" check="all" comment="cdosys.dll is less than 6.5.6749.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:661"/>
      <state state_ref="oval:org.mitre.oval:ste:1017"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:1140" version="1" check="at least one" comment="Networking UUCP Utilities - Usr (SUNWbnuu) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:818"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:1139" version="1" check="at least one" comment="Patch 106952-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:817"/>
      <state state_ref="oval:org.mitre.oval:ste:1020"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1138" version="1" check="at least one" comment="Patch 111570-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:657"/>
      <state state_ref="oval:org.mitre.oval:ste:1019"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1137" version="1" check="at least one" comment="Patch 113322-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:655"/>
      <state state_ref="oval:org.mitre.oval:ste:1018"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:1142" version="1" check="at least one" comment="the version of Fontsub.dll is less than 5.2.3790.426" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:668"/>
      <state state_ref="oval:org.mitre.oval:ste:1022"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1141" version="1" check="at least one" comment="the version of T2embed.dll is less than 5.2.3790.426" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:667"/>
      <state state_ref="oval:org.mitre.oval:ste:1021"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2697" version="1" check="at least one" comment="the patch KB901214 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1545"/>
      <state state_ref="oval:org.mitre.oval:ste:2519"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1143" version="1" check="at least one" comment="the version of mscms.dll is less than 5.2.3790.359" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:745"/>
      <state state_ref="oval:org.mitre.oval:ste:1023"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1144" version="1" check="all" comment="fetchmail RPM earlier than 0:6.2.5-6.el4.2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:819"/>
      <state state_ref="oval:org.mitre.oval:ste:1024"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1145" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.1.2600.2770" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:1025"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2936" version="1" check="at least one" comment="gdm version is less than 2.4.1.3-5.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1677"/>
      <state state_ref="oval:org.mitre.oval:ste:2751"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:3082" version="1" check="at least one" comment="the patch kb824146 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1755"/>
      <state state_ref="oval:org.mitre.oval:ste:2887"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2914" version="1" check="at least one" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:254"/>
      <state state_ref="oval:org.mitre.oval:ste:2730"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2790" version="1" check="at least one" comment="Win2K/XP/2003 service pack 5 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2610"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1148" version="1" check="all" comment="kernel RPM earlier than 0:2.4.21-32.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:822"/>
      <state state_ref="oval:org.mitre.oval:ste:1028"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1147" version="1" check="all" comment="kernel-hugemem RPM earlier than 0:2.4.21-32.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:821"/>
      <state state_ref="oval:org.mitre.oval:ste:1027"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1146" version="1" check="all" comment="kernel-smp RPM earlier than 0:2.4.21-32.0.1.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:820"/>
      <state state_ref="oval:org.mitre.oval:ste:1026"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1149" version="1" check="all" comment="shell32.dll is less than 6.0.2800.1751" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:1029"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2749" version="2" check="all" comment="PNG image rendering enabled in Internet Explorer" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1577"/>
      <state state_ref="oval:org.mitre.oval:ste:2570"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1150" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2668" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1030"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1152" version="1" check="all" comment="the version of dhtmled.ocx is less than 6.1.0.9231" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:377"/>
      <state state_ref="oval:org.mitre.oval:ste:1032"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1151" version="1" check="at least one" comment="the patch kb891781 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:823"/>
      <state state_ref="oval:org.mitre.oval:ste:1031"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:3468" version="1" check="at least one" comment="Patch PHNE_33427 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2678"/>
      <state state_ref="oval:org.mitre.oval:ste:3608"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3294" version="1" check="all" comment="HP Release B.11.04" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3271"/>
    </uname_test>
    <package_test id="oval:org.mitre.oval:tst:1161" version="1" check="at least one" comment="Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sv) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:828"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:1160" version="1" check="at least one" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkr5sl) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:827"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:1159" version="1" check="at least one" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrgdo) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:826"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:1158" version="1" check="at least one" comment=" Sun Enterprise Authentication Mechanism (SEAM, SUNWkrggl) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:825"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:1157" version="1" check="at least one" comment="Patch 112536-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:296"/>
      <state state_ref="oval:org.mitre.oval:ste:1036"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1156" version="1" check="at least one" comment="Patch 112908-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:442"/>
      <state state_ref="oval:org.mitre.oval:ste:1035"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1155" version="1" check="at least one" comment="Patch 112237-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:447"/>
      <state state_ref="oval:org.mitre.oval:ste:1034"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1154" version="1" check="at least one" comment="Patch 112390-07 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:446"/>
      <state state_ref="oval:org.mitre.oval:ste:1033"/>
    </patch_test>
    <textfilecontent_test id="oval:org.mitre.oval:tst:1153" version="1" check="all" comment="/etc/krb5/krb5.conf is configured with a kerberos domain" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes>
        <oval-def:note>Rough translation of the Sun recommended test of: % grep default_realm /etc/krb5/krb5.conf | grep -v ___default_realm___  default_realm = EXAMPLE.COM</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:824"/>
    </textfilecontent_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2667" version="1" check="all" comment="gzip RPM earlier than 0:1.3.3-12rhel3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1529"/>
      <state state_ref="oval:org.mitre.oval:ste:2491"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1162" version="1" check="all" comment="/usr/bin/zgrep is executable by any user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:829"/>
      <state state_ref="oval:org.mitre.oval:ste:1037"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1163" version="1" check="all" comment="nwwks.dll is less than 5.1.2600.1727" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:652"/>
      <state state_ref="oval:org.mitre.oval:ste:1038"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1164" version="1" check="at least one" comment="the version of sxs.dll is less than 5.2.3790.121" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:336"/>
      <state state_ref="oval:org.mitre.oval:ste:1039"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1166" version="1" check="at least one" comment="DirectX 9.0-gold Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1041"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1165" version="1" check="at least one" comment="DirectX 9.0a Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1040"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1167" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2577" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1042"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3126" version="1" check="at least one" comment="File snmpdx exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1778"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3125" version="1" check="at least one" comment="Patch 108869-16 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:867"/>
      <state state_ref="oval:org.mitre.oval:ste:2927"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:3135" version="1" check="at least one" comment="inetd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1782"/>
      <state state_ref="oval:org.mitre.oval:ste:2934"/>
    </process_test>
    <inetd_test id="oval:org.mitre.oval:tst:3103" version="1" check="at least one" comment="inetd.conf contains rpc.ttdbserverd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1763"/>
      <state state_ref="oval:org.mitre.oval:ste:2908"/>
    </inetd_test>
    <package_test id="oval:org.mitre.oval:tst:1169" version="1" check="all" comment="Toolktalk (SUNWtltk/SUNWtltkx) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:831"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:1168" version="1" check="at least one" comment="Patch 112808-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:830"/>
      <state state_ref="oval:org.mitre.oval:ste:1043"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:2511" version="1" check="all" comment="HP Release B.11.23" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2351"/>
    </uname_test>
    <file_test id="oval:org.mitre.oval:tst:2390" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2800.1528" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2238"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1466" version="1" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:1324"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1465" version="1" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:1323"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1464" version="1" check="at least one" comment="Internet Explorer 5.5 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:1322"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1461" version="1" check="at least one" comment="Patch Q295106 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:994"/>
      <state state_ref="oval:org.mitre.oval:ste:1319"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1171" version="1" check="at least one" comment="File %windir%\system32\mshtml.dll version is less than 5.50.4616.200" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1045"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1170" version="1" check="at least one" comment="File %windir%\system32\urlmon.dll version is less than 5.50.4701.2400" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1044"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1173" version="1" check="at least one" comment="DirectX 8.x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1047"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1172" version="1" check="at least one" comment="Patch Windows2000-KB819696-x86-ENU.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:832"/>
      <state state_ref="oval:org.mitre.oval:ste:1046"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3123" version="1" check="at least one" comment="Internet Explorer 5.5 Service Pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2926"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1454" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.50.4926.2500" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1312"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1509" version="1" check="at least one" comment="the version of schannel.dll is less than 5.2.3790.132" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1002"/>
      <state state_ref="oval:org.mitre.oval:ste:1363"/>
    </file_test>
    <metabase_test id="oval:org.mitre.oval:tst:1508" version="1" check="at least one" comment="SSL is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1014"/>
    </metabase_test>
    <registry_test id="oval:org.mitre.oval:tst:1503" version="1" check="at least one" comment="PCT support is disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1011"/>
      <state state_ref="oval:org.mitre.oval:ste:1358"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1177" version="1" check="at least one" comment="Internet Explorer 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:1051"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1176" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.449" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1050"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1175" version="1" check="at least one" comment="Server 2003 IE Enhanced Security (Administror) is installed and set." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:834"/>
      <state state_ref="oval:org.mitre.oval:ste:1049"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1174" version="1" check="at least one" comment="Server 2003 IE Enhanced Security (User) is installed and set." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:833"/>
      <state state_ref="oval:org.mitre.oval:ste:1048"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2938" version="1" check="at least one" comment="the version of ntdll.dll is less than 5.0.2195.6685" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1679"/>
      <state state_ref="oval:org.mitre.oval:ste:2753"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2937" version="1" check="at least one" comment="the patch q815021 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1678"/>
      <state state_ref="oval:org.mitre.oval:ste:2752"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2535" version="1" check="at least one" comment="Mozilla Suite version 1.7.10 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1445"/>
      <state state_ref="oval:org.mitre.oval:ste:2370"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2534" version="1" check="at least one" comment="Mozilla Suite version 1.7.10 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:2369"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2533" version="1" check="at least one" comment="Firefox version 1.0.6 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:2368"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2532" version="1" check="at least one" comment="Mozilla Firefox version 1.0.6 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1444"/>
      <state state_ref="oval:org.mitre.oval:ste:2367"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2853" version="1" check="at least one" comment="Patch KB897715 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1635"/>
      <state state_ref="oval:org.mitre.oval:ste:2671"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1514" version="1" check="at least one" comment="Outlook Express 5.5 SP2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:566"/>
      <state state_ref="oval:org.mitre.oval:ste:1368"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1178" version="1" check="at least one" comment="the version of inetcomm.dll is less than 5.50.4952.2800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1052"/>
    </file_test>
    <process_test id="oval:org.mitre.oval:tst:2432" version="1" check="all" comment="postmaster (the PostgreSQL master daemon) is running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1383"/>
    </process_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1180" version="1" check="all" comment="rh-postgresql-contrib rpm is earlier than 0:7.3.10-1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:836"/>
      <state state_ref="oval:org.mitre.oval:ste:1053"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1179" version="1" check="all" comment="/usr/lib/pgsql/tsearch.so (PostgreSQL's tsearch module) exists as a regular file" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:835"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1182" version="1" check="at least one" comment="the version of Mapi32.dll is greater than or equal 6.0.6603.0 (Exchange 2000 Server,SP3 is installed)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:837"/>
      <state state_ref="oval:org.mitre.oval:ste:1055"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1181" version="1" check="at least one" comment="the version of Mapi32.dll is less than 6.0.6617.47" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:837"/>
      <state state_ref="oval:org.mitre.oval:ste:1054"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2386" version="1" check="all" comment="bzip2 RPM earlier than 0:1.0.2-11.EL3.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1363"/>
      <state state_ref="oval:org.mitre.oval:ste:2235"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1183" version="1" check="all" comment="/usr/bin/bzgrep is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:838"/>
      <state state_ref="oval:org.mitre.oval:ste:1056"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1186" version="1" check="at least one" comment="Windows 95 or 98 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:629"/>
      <state state_ref="oval:org.mitre.oval:ste:1059"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1185" version="1" check="at least one" comment="TCP/IP NetBIOS not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:840"/>
      <state state_ref="oval:org.mitre.oval:ste:1058"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1184" version="1" check="at least one" comment="WINS Client binding not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:839"/>
      <state state_ref="oval:org.mitre.oval:ste:1057"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1187" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2706" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1060"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1189" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.636.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:1062"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1188" version="1" check="at least one" comment="the version of ssnetlib.dll is less than 2000.80.636.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:841"/>
      <state state_ref="oval:org.mitre.oval:ste:1061"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1190" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.0.2195.6905" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:1063"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1195" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.1.2600.1715" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:1068"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1194" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.1.2600.2716" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:1067"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1193" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.2.3790.2483" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:1066"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1192" version="1" check="at least one" comment="the patch kb893756 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:846"/>
      <state state_ref="oval:org.mitre.oval:ste:1065"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1191" version="1" check="at least one" comment="the Telephony service is enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:845"/>
      <state state_ref="oval:org.mitre.oval:ste:1064"/>
    </registry_test>
    <patch_test id="oval:org.mitre.oval:tst:1197" version="1" check="at least one" comment="Patch 119985-02 or later installed (SPARC-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:848"/>
      <state state_ref="oval:org.mitre.oval:ste:1070"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1196" version="1" check="at least one" comment="Patch 122082-01 or later installed (x86-10)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:847"/>
      <state state_ref="oval:org.mitre.oval:ste:1069"/>
    </patch_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2652" version="1" check="at least one" comment="Red Hat Enterprise 4 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:2477"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2651" version="1" check="all" comment="mozilla RPM is earlier than 37:1.7.10-1.4.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <oval-def:notes>
        <oval-def:note>Multiple RPMs were updated in this release, but all but mozilla-nspr have mozilla-with-their-same-version as an installation dependency.  So, if mozilla is up to date, mozilla-chat, mozilla-devel, ... , mozilla-js-debugger are all up to date.  Mozilla itself requires that mozilla-nspr and mozilla-nss be installed with the same version as itself.  This closes the loop -- if mozilla is up to date, so are the other mozilla-FOO RPMs.</oval-def:note>
      </oval-def:notes>
      <object object_ref="oval:org.mitre.oval:obj:1519"/>
      <state state_ref="oval:org.mitre.oval:ste:2476"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:2650" version="1" check="all" comment="/usr/bin/mozilla is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1030"/>
      <state state_ref="oval:org.mitre.oval:ste:2475"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1198" version="1" check="at least one" comment="the version of comsvcs.dll is less than 2001.12.4414.53" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:849"/>
      <state state_ref="oval:org.mitre.oval:ste:1071"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1200" version="1" check="at least one" comment="the version of ole32.dll is less than 5.1.2600.1720" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:1073"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1199" version="1" check="at least one" comment="the version of rpcss.dll is less than 5.1.2600.1720" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:709"/>
      <state state_ref="oval:org.mitre.oval:ste:1072"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1202" version="1" check="at least one" comment="Exchange Server 2003,SP2 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:732"/>
      <state state_ref="oval:org.mitre.oval:ste:1075"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1201" version="1" check="all" comment="mdbmsg.dll is less than 6.5.7650.28" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:731"/>
      <state state_ref="oval:org.mitre.oval:ste:1074"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2939" version="1" check="at least one" comment="evolution version is less than 1.2.2-5" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1680"/>
      <state state_ref="oval:org.mitre.oval:ste:2754"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:1204" version="2" check="at least one" comment="PowerPoint 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:850"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1203" version="2" check="at least one" comment="the version of PowerPnt.exe is less than 11.0.8024.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:553"/>
      <state state_ref="oval:org.mitre.oval:ste:1076"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1205" version="1" check="at least one" comment="File %windir%\System32\Msw3prt.dll is less than 5.0.2195.2956" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:851"/>
      <state state_ref="oval:org.mitre.oval:ste:1077"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1206" version="1" check="at least one" comment="the version of Jscript.dll is less than 5.6.0.8831" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:1078"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1207" version="1" check="at least one" comment="the version of comsvcs.dll is less than 2001.12.4720.130" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:849"/>
      <state state_ref="oval:org.mitre.oval:ste:1079"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1223" version="1" check="at least one" comment="openoffice version is less than 1.1.0-15.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:857"/>
      <state state_ref="oval:org.mitre.oval:ste:1095"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1222" version="1" check="at least one" comment="/usr/bin/oocalc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:856"/>
      <state state_ref="oval:org.mitre.oval:ste:1094"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1221" version="1" check="at least one" comment="/usr/bin/oocalc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:856"/>
      <state state_ref="oval:org.mitre.oval:ste:1093"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1220" version="1" check="at least one" comment="/usr/bin/oocalc is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:856"/>
      <state state_ref="oval:org.mitre.oval:ste:1092"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1219" version="1" check="at least one" comment="/usr/bin/oodraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:855"/>
      <state state_ref="oval:org.mitre.oval:ste:1091"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1218" version="1" check="at least one" comment="/usr/bin/oodraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:855"/>
      <state state_ref="oval:org.mitre.oval:ste:1090"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1217" version="1" check="at least one" comment="/usr/bin/oodraw is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:855"/>
      <state state_ref="oval:org.mitre.oval:ste:1089"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1216" version="1" check="at least one" comment="/usr/bin/ooffice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:854"/>
      <state state_ref="oval:org.mitre.oval:ste:1088"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1215" version="1" check="at least one" comment="/usr/bin/ooffice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:854"/>
      <state state_ref="oval:org.mitre.oval:ste:1087"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1214" version="1" check="at least one" comment="/usr/bin/ooffice is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:854"/>
      <state state_ref="oval:org.mitre.oval:ste:1086"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1213" version="1" check="at least one" comment="/usr/bin/ooimpress is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:853"/>
      <state state_ref="oval:org.mitre.oval:ste:1085"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1212" version="1" check="at least one" comment="/usr/bin/ooimpress is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:853"/>
      <state state_ref="oval:org.mitre.oval:ste:1084"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1211" version="1" check="at least one" comment="/usr/bin/ooimpress is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:853"/>
      <state state_ref="oval:org.mitre.oval:ste:1083"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1210" version="1" check="at least one" comment="/usr/bin/oowriter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:852"/>
      <state state_ref="oval:org.mitre.oval:ste:1082"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1209" version="1" check="at least one" comment="/usr/bin/oowriter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:852"/>
      <state state_ref="oval:org.mitre.oval:ste:1081"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1208" version="1" check="at least one" comment="/usr/bin/oowriter is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:852"/>
      <state state_ref="oval:org.mitre.oval:ste:1080"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1225" version="1" check="at least one" comment="the version of mf3216.dll is less than 5.1.2600.132" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:858"/>
      <state state_ref="oval:org.mitre.oval:ste:1097"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1224" version="1" check="at least one" comment="the version of mf3216.dll is less than 5.1.2600.1331" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:858"/>
      <state state_ref="oval:org.mitre.oval:ste:1096"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1227" version="1" check="at least one" comment="the version of Gdi32.dll is less than 5.0.2195.7069" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:622"/>
      <state state_ref="oval:org.mitre.oval:ste:1099"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1226" version="1" check="at least one" comment="the version of Mf3216.dll is less than 5.0.2195.6898" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:807"/>
      <state state_ref="oval:org.mitre.oval:ste:1098"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1228" version="1" check="at least one" comment="the version of comsvcs.dll is less than 2000.2.3511.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:849"/>
      <state state_ref="oval:org.mitre.oval:ste:1100"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2403" version="1" check="at least one" comment="Internet Explorer 6.0 Installed XP SP2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2251"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2331" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2722" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2183"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1229" version="1" check="at least one" comment="the version of cryptdlg.dll is less then 5.0.1558.6072" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:728"/>
      <state state_ref="oval:org.mitre.oval:ste:1101"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2744" version="1" check="at least one" comment="64-Bit (x64 architecture) version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1576"/>
      <state state_ref="oval:org.mitre.oval:ste:2565"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2671" version="1" check="at least one" comment="the version of hh.exe is less than 5.2.3790.315" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:859"/>
      <state state_ref="oval:org.mitre.oval:ste:2495"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2669" version="1" check="at least one" comment="the version of hh.exe is less than 5.2.3790.2435" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:859"/>
      <state state_ref="oval:org.mitre.oval:ste:2493"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2668" version="1" check="at least one" comment="the patch kb896358 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:802"/>
      <state state_ref="oval:org.mitre.oval:ste:2492"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1230" version="1" check="at least one" comment="the version of hh.exe is less than 5.2.3790.2453" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:859"/>
      <state state_ref="oval:org.mitre.oval:ste:1102"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1232" version="1" check="at least one" comment="the version of crypt32.dll is less than 5.131.2600.1123" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:861"/>
      <state state_ref="oval:org.mitre.oval:ste:1104"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1231" version="1" check="at least one" comment="the patch Q329115 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:860"/>
      <state state_ref="oval:org.mitre.oval:ste:1103"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1494" version="1" check="at least one" comment="machine is a member of a domain" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1009"/>
      <state state_ref="oval:org.mitre.oval:ste:1351"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1234" version="1" check="at least one" comment="the version of msgina.dll is less than 5.1.2600.128" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:862"/>
      <state state_ref="oval:org.mitre.oval:ste:1106"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1233" version="1" check="at least one" comment="the version of msgina.dll is less than 5.1.2600.1343" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:862"/>
      <state state_ref="oval:org.mitre.oval:ste:1105"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1238" version="1" check="at least one" comment="the 32-bit version of zipfldr.dll is less than 6.0.2750.167" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:339"/>
      <state state_ref="oval:org.mitre.oval:ste:1110"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1237" version="1" check="at least one" comment="the 32-bit version of zipfldr.dll is less than 6.0.2800.1584" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:339"/>
      <state state_ref="oval:org.mitre.oval:ste:1109"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1236" version="1" check="at least one" comment="the patch q873376 is installed (Hotfix key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:864"/>
      <state state_ref="oval:org.mitre.oval:ste:1108"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1235" version="1" check="at least one" comment="Compressed Folders with zipfldr.dll are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:863"/>
      <state state_ref="oval:org.mitre.oval:ste:1107"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1239" version="1" check="at least one" comment="the software MailSite Express version 6.1.20 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:865"/>
      <state state_ref="oval:org.mitre.oval:ste:1111"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3020" version="1" check="at least one" comment="Patch Q293826 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1728"/>
      <state state_ref="oval:org.mitre.oval:ste:2828"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1240" version="1" check="at least one" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.3649" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:866"/>
      <state state_ref="oval:org.mitre.oval:ste:1112"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1484" version="1" check="at least one" comment="openssl version is less than 0.9.7a-20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1007"/>
      <state state_ref="oval:org.mitre.oval:ste:1341"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1483" version="1" check="at least one" comment="openssl-devel version is less than 0.9.7a-20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1006"/>
      <state state_ref="oval:org.mitre.oval:ste:1340"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1482" version="1" check="at least one" comment="openssl-perl version is less than 0.9.7a-20" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1005"/>
      <state state_ref="oval:org.mitre.oval:ste:1339"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1481" version="1" check="at least one" comment="openssl096 version is less than 0.9.6-25.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1004"/>
      <state state_ref="oval:org.mitre.oval:ste:1338"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1480" version="1" check="at least one" comment="openssl096b version is less than 0.9.6b-15" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1003"/>
      <state state_ref="oval:org.mitre.oval:ste:1337"/>
    </rpminfo_test>
    <process_test id="oval:org.mitre.oval:tst:3124" version="1" check="at least one" comment="snmpdx running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1777"/>
    </process_test>
    <package_test id="oval:org.mitre.oval:tst:1243" version="1" check="at least one" comment="Solstice Enterprise Agents SNMP (SUNWsasnm) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:869"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:1242" version="1" check="at least one" comment="Patch 107709-18 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:868"/>
      <state state_ref="oval:org.mitre.oval:ste:1114"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1241" version="1" check="at least one" comment="Patch 108869-15 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:867"/>
      <state state_ref="oval:org.mitre.oval:ste:1113"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:1244" version="1" check="at least one" comment="the version of umandlg.dll is less than 1.0.0.4" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:870"/>
      <state state_ref="oval:org.mitre.oval:ste:1115"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1247" version="1" check="at least one" comment="Win2K/XP/2003 service pack 4 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:1118"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1246" version="1" check="at least one" comment="the version of Spoolsv.exe is less than 5.0.2195.7059" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:223"/>
      <state state_ref="oval:org.mitre.oval:ste:1117"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1245" version="1" check="at least one" comment="the patch KB896423 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:871"/>
      <state state_ref="oval:org.mitre.oval:ste:1116"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1336" version="1" check="at least one" comment="File Xorg exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:924"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:1254" version="1" check="at least one" comment="Patch 108652-94 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:876"/>
      <state state_ref="oval:org.mitre.oval:ste:1124"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1253" version="1" check="at least one" comment="Patch 112785-52 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:211"/>
      <state state_ref="oval:org.mitre.oval:ste:1123"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1252" version="1" check="at least one" comment="Patch 119059-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:875"/>
      <state state_ref="oval:org.mitre.oval:ste:1122"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1251" version="1" check="at least one" comment="Patch 108653-83 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:874"/>
      <state state_ref="oval:org.mitre.oval:ste:1121"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1250" version="1" check="at least one" comment="Patch 112786-41 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:210"/>
      <state state_ref="oval:org.mitre.oval:ste:1120"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:1249" version="1" check="at least one" comment="Patch 119060-08 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:873"/>
      <state state_ref="oval:org.mitre.oval:ste:1119"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:1248" version="1" check="at least one" comment="The Xsun X server is running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:872"/>
    </process_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1255" version="1" check="at least one" comment="cvs version is less than 1.11.2-18" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:877"/>
      <state state_ref="oval:org.mitre.oval:ste:1125"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1257" version="1" check="at least one" comment="the version of ole32.dll is less than 4.0.1381.7263" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:1127"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1256" version="1" check="at least one" comment="the version of ole32.dll is less than 4.0.1381.33562" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:406"/>
      <state state_ref="oval:org.mitre.oval:ste:1126"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1395" version="1" check="at least one" comment="Patch Q823718 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:962"/>
      <state state_ref="oval:org.mitre.oval:ste:1257"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1260" version="1" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9001.40" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:1130"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1259" version="1" check="at least one" comment="File %windir%\System32\odbcbcp.dll is less than 2000.81.9041.40" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:1129"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1258" version="1" check="at least one" comment="DataAccess Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:1128"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2483" version="1" check="at least one" comment="Red Hat Enterprise 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:2327"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1262" version="1" check="all" comment="fetchmail RPM older than 0:6.2.0-3.el3.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:880"/>
      <state state_ref="oval:org.mitre.oval:ste:1132"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1261" version="1" check="all" comment="/usr/bin/fetchmail is executable by any user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:879"/>
      <state state_ref="oval:org.mitre.oval:ste:1131"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2439" version="1" check="at least one" comment="A pre-release of SeaMonkey 1.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1385"/>
      <state state_ref="oval:org.mitre.oval:ste:2284"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2438" version="1" check="at least one" comment="A pre-release of SeaMonkey 1.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:794"/>
      <state state_ref="oval:org.mitre.oval:ste:2283"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1268" version="1" check="at least one" comment="Mozilla Firefox version 1.0.7 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:883"/>
      <state state_ref="oval:org.mitre.oval:ste:1138"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1267" version="1" check="at least one" comment="Firefox version 1.0.7 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:1137"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1266" version="1" check="at least one" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:882"/>
      <state state_ref="oval:org.mitre.oval:ste:1136"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1265" version="1" check="at least one" comment="Mozilla Thunderbird version 1.0.7 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:1135"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1264" version="1" check="at least one" comment="Mozilla Suite version 1.7.12 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:1134"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1263" version="1" check="at least one" comment="Mozilla Suite version 1.7.12 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:881"/>
      <state state_ref="oval:org.mitre.oval:ste:1133"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1272" version="1" check="at least one" comment="the version of helpctr.exe is less than 5.2.3790.161" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:886"/>
      <state state_ref="oval:org.mitre.oval:ste:1141"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:4124" version="1" check="all" comment="800-series HP" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3073"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:3993" version="1" check="at least one" comment="Patch PHCO_28847 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:1883"/>
      <state state_ref="oval:org.mitre.oval:ste:3737"/>
    </patch_test>
    <swlist_test id="oval:org.mitre.oval:tst:3858" version="1" check="at least one" comment="DCE-Core.DCE-CORE-SHLIB is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2529"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:3857" version="1" check="at least one" comment="SW-DIST.SD-AGENT is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2602"/>
    </swlist_test>
    <patch_test id="oval:org.mitre.oval:tst:3649" version="1" check="at least one" comment="Patch PHSS_29963 or subsequent is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:2770"/>
      <state state_ref="oval:org.mitre.oval:ste:3919"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3571" version="1" check="all" comment="HP Release B.11.00" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3813"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:3443" version="1" check="all" comment="700-series HP" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:2759"/>
      <state state_ref="oval:org.mitre.oval:ste:3773"/>
    </uname_test>
    <registry_test id="oval:org.mitre.oval:tst:2703" version="1" check="at least one" comment="this is an NT Workstation" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1550"/>
      <state state_ref="oval:org.mitre.oval:ste:2525"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1499" version="1" check="at least one" comment="the patch kb828741 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1010"/>
      <state state_ref="oval:org.mitre.oval:ste:1354"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1383" version="1" check="at least one" comment="COM Internet Services are enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:955"/>
      <state state_ref="oval:org.mitre.oval:ste:1245"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1274" version="1" check="at least one" comment="machine has followed the GDR update path and rpcproxy.dll is less than 5.2.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:887"/>
      <state state_ref="oval:org.mitre.oval:ste:1143"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1273" version="1" check="at least one" comment="machine has followed the QFE update path and rpcproxy.dll is less than 5.2.3790.141" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:887"/>
      <state state_ref="oval:org.mitre.oval:ste:1142"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2942" version="1" check="at least one" comment="the version of locator.exe is less than 4.0.1381.7202" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1683"/>
      <state state_ref="oval:org.mitre.oval:ste:2757"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2941" version="1" check="at least one" comment="Patch Q810833 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1682"/>
      <state state_ref="oval:org.mitre.oval:ste:2756"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2940" version="1" check="at least one" comment="Locator Enabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1681"/>
      <state state_ref="oval:org.mitre.oval:ste:2755"/>
    </registry_test>
    <uname_test id="oval:org.mitre.oval:tst:2515" version="1" check="all" comment="700-series HP" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2355"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:2513" version="1" check="all" comment="800-series HP" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2353"/>
    </uname_test>
    <swlist_test id="oval:org.mitre.oval:tst:1279" version="1" check="at least one" comment="InternetSrvcs.INETSVCS-RUN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:891"/>
      <state state_ref="oval:org.mitre.oval:ste:1148"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:1278" version="1" check="at least one" comment="InternetSrvcs.INET-ENG-A-MAN is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:890"/>
      <state state_ref="oval:org.mitre.oval:ste:1147"/>
    </swlist_test>
    <swlist_test id="oval:org.mitre.oval:tst:1277" version="1" check="at least one" comment="VirtualVaultOS.VVOS-AUX-IA is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:889"/>
      <state state_ref="oval:org.mitre.oval:ste:1146"/>
    </swlist_test>
    <uname_test id="oval:org.mitre.oval:tst:1276" version="1" check="all" comment="HP Release B.11.04" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:1145"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:1275" version="1" check="at least one" comment="Patch PHNE_24395 or later is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <object object_ref="oval:org.mitre.oval:obj:888"/>
      <state state_ref="oval:org.mitre.oval:ste:1144"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2855" version="1" check="at least one" comment="Outlook Express 6 for Windows 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:566"/>
      <state state_ref="oval:org.mitre.oval:ste:2673"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1281" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.00.3790.137" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1150"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1280" version="1" check="at least one" comment="the patch kb837009 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:892"/>
      <state state_ref="oval:org.mitre.oval:ste:1149"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1296" version="1" check="at least one" comment="DirectX 7.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1165"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1295" version="1" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2195.6927" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:1164"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1294" version="1" check="at least one" comment="Patch Windows2000-KB839643-x86-ENU.EXE Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:897"/>
      <state state_ref="oval:org.mitre.oval:ste:1163"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1293" version="1" check="at least one" comment="DirectX 8.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1162"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1292" version="1" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.0.2258.410" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:1161"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1291" version="1" check="at least one" comment="Patch DirectX80-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:896"/>
      <state state_ref="oval:org.mitre.oval:ste:1160"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1290" version="1" check="at least one" comment="DirectX 8.1x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1159"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1289" version="1" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.1.2600.891" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:1158"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1288" version="1" check="at least one" comment="Patch DirectX81-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:895"/>
      <state state_ref="oval:org.mitre.oval:ste:1157"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1287" version="1" check="at least one" comment="DirectX 8.2x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1156"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1286" version="1" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.2.3677.144" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:1155"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1285" version="1" check="at least one" comment="Patch DirectX82-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:894"/>
      <state state_ref="oval:org.mitre.oval:ste:1154"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1284" version="1" check="at least one" comment="DirectX 9.0x Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:499"/>
      <state state_ref="oval:org.mitre.oval:ste:1153"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1283" version="1" check="at least one" comment="File %windir%\system32\dplayx.dll version is less than 5.3.0.903" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:450"/>
      <state state_ref="oval:org.mitre.oval:ste:1152"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1282" version="1" check="at least one" comment="Patch DirectX90-KB839643-x86-ENU Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:893"/>
      <state state_ref="oval:org.mitre.oval:ste:1151"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3015" version="1" check="at least one" comment="Internet Explorer 5.01 Service Pack 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2824"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2751" version="1" check="at least one" comment="the version of mshtml.dll is less than 5.0.3541.2700" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2572"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2750" version="1" check="at least one" comment="the patch kb883939 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1578"/>
      <state state_ref="oval:org.mitre.oval:ste:2571"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2591" version="1" check="at least one" comment="SQL Server 2000 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1470"/>
      <state state_ref="oval:org.mitre.oval:ste:2424"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1303" version="1" check="at least one" comment="the version of sqlservr.exe is less than 2000.80.650.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:843"/>
      <state state_ref="oval:org.mitre.oval:ste:1172"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1302" version="1" check="at least one" comment="the version of odsole70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:903"/>
      <state state_ref="oval:org.mitre.oval:ste:1171"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1301" version="1" check="at least one" comment="the version of xpqueue.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:902"/>
      <state state_ref="oval:org.mitre.oval:ste:1170"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1300" version="1" check="at least one" comment="the version of xprepl.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:901"/>
      <state state_ref="oval:org.mitre.oval:ste:1169"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1299" version="1" check="at least one" comment="the version of xplog70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:900"/>
      <state state_ref="oval:org.mitre.oval:ste:1168"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1298" version="1" check="at least one" comment="the version of xpweb70.dll is less than 2000.80.606.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:899"/>
      <state state_ref="oval:org.mitre.oval:ste:1167"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1297" version="1" check="at least one" comment="the version of xpstar.dll is less than 2000.80.628.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:898"/>
      <state state_ref="oval:org.mitre.oval:ste:1166"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1306" version="1" check="at least one" comment="NetBIOS Bind not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:906"/>
      <state state_ref="oval:org.mitre.oval:ste:1175"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1305" version="1" check="at least one" comment="NetBIOS Export not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:905"/>
      <state state_ref="oval:org.mitre.oval:ste:1174"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1304" version="1" check="at least one" comment="NetBIOS Route not disabled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:904"/>
      <state state_ref="oval:org.mitre.oval:ste:1173"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3079" version="1" check="at least one" comment="Win2K/XP/2003 service pack 3 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2884"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1307" version="1" check="at least one" comment="Remote access to registry not controlled" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:907"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1311" version="1" check="at least one" comment="Microsoft Exchange 2000 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:911"/>
      <state state_ref="oval:org.mitre.oval:ste:1177"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1310" version="1" check="at least one" comment="File %ExchangeInstallDir%\bin\mad.exe is less than 6.0.5770.21" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:910"/>
      <state state_ref="oval:org.mitre.oval:ste:1176"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1309" version="1" check="at least one" comment="Patch Q316056 installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:909"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1308" version="1" check="at least one" comment="Everyone group given remote access permissions" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:908"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3097" version="1" check="at least one" comment="this is an NT Terminal Server" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1761"/>
      <state state_ref="oval:org.mitre.oval:ste:2902"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3089" version="1" check="at least one" comment="Windows NT 4.0 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:419"/>
      <state state_ref="oval:org.mitre.oval:ste:2894"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3036" version="1" check="at least one" comment="Windows NT 4.0 Security Roll-up Package" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1737"/>
      <state state_ref="oval:org.mitre.oval:ste:2843"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1313" version="1" check="at least one" comment="File %windir%\system32\winlogon.exe version is less than 4.0.1381.7058" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:913"/>
      <state state_ref="oval:org.mitre.oval:ste:1179"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1312" version="1" check="at least one" comment="Windows NT Server 4.0, Terminal Server Edition Security Rollup Package" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:912"/>
      <state state_ref="oval:org.mitre.oval:ste:1178"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2339" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2900.2873" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:2190"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3006" version="1" check="at least one" comment="File rpc.yppasswdd exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1721"/>
    </file_test>
    <process_test id="oval:org.mitre.oval:tst:3004" version="1" check="at least one" comment="rpc.yppasswdd running" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1719"/>
    </process_test>
    <patch_test id="oval:org.mitre.oval:tst:2943" version="1" check="at least one" comment="Patch 111590-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:1684"/>
      <state state_ref="oval:org.mitre.oval:ste:2758"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:3099" version="1" check="at least one" comment="IIS 4.0 Major Version" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1754"/>
      <state state_ref="oval:org.mitre.oval:ste:2904"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3038" version="1" check="at least one" comment="Patch Q295534 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1739"/>
      <state state_ref="oval:org.mitre.oval:ste:2845"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3037" version="1" check="at least one" comment="Patch Q301625 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1738"/>
      <state state_ref="oval:org.mitre.oval:ste:2844"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1314" version="1" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 4.2.764.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:914"/>
      <state state_ref="oval:org.mitre.oval:ste:1180"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1315" version="1" check="at least one" comment="kernel version is less than 2.4.21-15.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:915"/>
      <state state_ref="oval:org.mitre.oval:ste:1181"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:3035" version="2" check="at least one" comment="this is an NT Server (domain controller)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1550"/>
      <state state_ref="oval:org.mitre.oval:ste:2842"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1511" version="1" check="at least one" comment="the version of lsasrv.dll is less than 5.0.2195.6902" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:512"/>
      <state state_ref="oval:org.mitre.oval:ste:1365"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1318" version="1" check="at least one" comment="Win2K/XP/2003 service pack 2 (or earlier) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:1184"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1317" version="1" check="at least one" comment="the version of shell32.dll is less than 6.0.2900.2578" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:253"/>
      <state state_ref="oval:org.mitre.oval:ste:1183"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1316" version="1" check="at least one" comment="Drag-and-Drop disabled when set to 3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:916"/>
      <state state_ref="oval:org.mitre.oval:ste:1182"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3119" version="1" check="at least one" comment="the patch q321232 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1774"/>
      <state state_ref="oval:org.mitre.oval:ste:2922"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3118" version="1" check="at least one" comment="the patch q323759 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1773"/>
      <state state_ref="oval:org.mitre.oval:ste:2921"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3117" version="1" check="at least one" comment="the patch q328970 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1772"/>
      <state state_ref="oval:org.mitre.oval:ste:2920"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3116" version="1" check="at least one" comment="the patch q324929 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1771"/>
      <state state_ref="oval:org.mitre.oval:ste:2919"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3115" version="1" check="at least one" comment="the patch q810847 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1770"/>
      <state state_ref="oval:org.mitre.oval:ste:2918"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3114" version="1" check="at least one" comment="the patch q813489 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1769"/>
      <state state_ref="oval:org.mitre.oval:ste:2917"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3113" version="1" check="at least one" comment="the patch q818529 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1768"/>
      <state state_ref="oval:org.mitre.oval:ste:2916"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3112" version="1" check="at least one" comment="the patch q822925 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1767"/>
      <state state_ref="oval:org.mitre.oval:ste:2915"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3111" version="1" check="at least one" comment="the patch q828750 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1766"/>
      <state state_ref="oval:org.mitre.oval:ste:2914"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3110" version="1" check="at least one" comment="the patch q824145 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1765"/>
      <state state_ref="oval:org.mitre.oval:ste:2913"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3090" version="1" check="at least one" comment="Internet Explorer 6 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2895"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2588" version="1" check="at least one" comment="the patch q832894 is installed (Installed Components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1469"/>
      <state state_ref="oval:org.mitre.oval:ste:2421"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1460" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.2712.0300" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1318"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1459" version="1" check="at least one" comment="Patch Q313675 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:993"/>
      <state state_ref="oval:org.mitre.oval:ste:1317"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1458" version="1" check="at least one" comment="Patch Q316059.exe Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:992"/>
      <state state_ref="oval:org.mitre.oval:ste:1316"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1457" version="1" check="at least one" comment="Patch Q319282 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:991"/>
      <state state_ref="oval:org.mitre.oval:ste:1315"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1456" version="1" check="at least one" comment="Use Machine Settings" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:990"/>
      <state state_ref="oval:org.mitre.oval:ste:1314"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1455" version="1" check="at least one" comment="File Downloads Allowed In At Least One Zone" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:989"/>
      <state state_ref="oval:org.mitre.oval:ste:1313"/>
    </registry_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1342" version="1" check="at least one" comment="kernel version is less than 2.4.21-15.EL" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:930"/>
      <state state_ref="oval:org.mitre.oval:ste:1204"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:3098" version="1" check="at least one" comment="IIS minor version equals 0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:938"/>
      <state state_ref="oval:org.mitre.oval:ste:2903"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1447" version="1" check="at least one" comment="File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:866"/>
      <state state_ref="oval:org.mitre.oval:ste:1305"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1512" version="1" check="at least one" comment="the patch kb837009 is installed (installed components key)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1016"/>
      <state state_ref="oval:org.mitre.oval:ste:1366"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1355" version="1" check="at least one" comment="Outlook Express 6 SP1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:566"/>
      <state state_ref="oval:org.mitre.oval:ste:1217"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1319" version="1" check="at least one" comment="the version of inetcomm.dll is less than 6.00.2800.1409" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:385"/>
      <state state_ref="oval:org.mitre.oval:ste:1185"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:3153" version="1" check="at least one" comment="Red Hat 9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:2949"/>
    </rpminfo_test>
    <uname_test id="oval:org.mitre.oval:tst:3152" version="1" check="at least one" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2948"/>
    </uname_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2985" version="1" check="at least one" comment="ethereal version is less than 0.9.13-1.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1706"/>
      <state state_ref="oval:org.mitre.oval:ste:2798"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2984" version="1" check="at least one" comment="ethereal-gnome version is less than 0.9.13-1.90.1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1705"/>
      <state state_ref="oval:org.mitre.oval:ste:2797"/>
    </rpminfo_test>
    <registry_test id="oval:org.mitre.oval:tst:3094" version="1" check="at least one" comment="Patch Q327696 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1759"/>
      <state state_ref="oval:org.mitre.oval:ste:2899"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3093" version="1" check="at least one" comment="Patch Q811114 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1758"/>
      <state state_ref="oval:org.mitre.oval:ste:2898"/>
    </registry_test>
    <registry_test check="at least one" comment="IIS major version equals 5" id="oval:org.mitre.oval:tst:3081" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1754"/>
      <state state_ref="oval:org.mitre.oval:ste:2886"/>
    </registry_test>
    <registry_test check="at least one" comment="IIS 5.1 Minor Version" id="oval:org.mitre.oval:tst:1357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:938"/>
      <state state_ref="oval:org.mitre.oval:ste:1219"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1356" version="1" check="at least one" comment="File %windir%\System32\w3svc.dll is less than 5.1.2600.1125" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:914"/>
      <state state_ref="oval:org.mitre.oval:ste:1218"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1322" version="1" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:886"/>
      <state state_ref="oval:org.mitre.oval:ste:1188"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1321" version="1" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.1515" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:886"/>
      <state state_ref="oval:org.mitre.oval:ste:1187"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1320" version="1" check="at least one" comment="the patch kb840374 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:917"/>
      <state state_ref="oval:org.mitre.oval:ste:1186"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1324" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.137" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:1190"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1323" version="1" check="at least one" comment="the version of msasn1.dll is less than 5.1.2600.1362" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:844"/>
      <state state_ref="oval:org.mitre.oval:ste:1189"/>
    </file_test>
    <inetlisteningservers_test id="oval:org.mitre.oval:tst:1630" version="1" check="at least one" comment="httpd is listening on the network" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1101"/>
      <state state_ref="oval:org.mitre.oval:ste:1482"/>
    </inetlisteningservers_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1327" version="1" check="at least one" comment="squirrelmail rpm version prior to 1.4.3-0.e3.1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:920"/>
      <state state_ref="oval:org.mitre.oval:ste:1191"/>
    </rpminfo_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1326" version="1" check="at least one" comment="php rpm is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:919"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1325" version="1" check="at least one" comment="/etc/httpd/modules/libphp4.so exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:918"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2951" version="1" check="at least one" comment="use machine settings rather than individual user settings" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:990"/>
      <state state_ref="oval:org.mitre.oval:ste:2766"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2919" version="1" check="at least one" comment="Internet Explorer 6 Service Pack 1 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2735"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2917" version="1" check="at least one" comment="ActiveX controls are enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1671"/>
      <state state_ref="oval:org.mitre.oval:ste:2733"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2916" version="1" check="at least one" comment="ActiveX controls are enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:988"/>
      <state state_ref="oval:org.mitre.oval:ste:2732"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2812" version="1" check="at least one" comment="active scripting is enabled for the current user" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1609"/>
      <state state_ref="oval:org.mitre.oval:ste:2632"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2811" version="1" check="at least one" comment="active scripting is enabled for the local machine" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1608"/>
      <state state_ref="oval:org.mitre.oval:ste:2631"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1329" version="1" check="all" comment="machine has followed the GDR update path and mshtml.dll is less than 6.0.2800.1491" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1193"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1328" version="1" check="all" comment="machine has followed the QFE update path and mshtml.dll is less than 6.0.2800.1492" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:1192"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1331" version="1" check="at least one" comment="the version of evtgprov.dll is less than 5.1.2600.136" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:921"/>
      <state state_ref="oval:org.mitre.oval:ste:1195"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1330" version="1" check="at least one" comment="the version of evtgprov.dll is less than 5.1.2600.1363" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:921"/>
      <state state_ref="oval:org.mitre.oval:ste:1194"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:30" version="1" check="at least one" comment="Microsoft XML Core Services 4 is installed." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:191"/>
    </file_test>
    <package_test id="oval:org.mitre.oval:tst:675" version="1" check="at least one" comment="CDE Desktop Window Manager (SUNWdtwm) installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:539"/>
    </package_test>
    <uname_test id="oval:org.mitre.oval:tst:2459" version="1" check="at least one" comment="Solaris 10 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2303"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:209" version="1" check="at least one" comment="Patch 118953-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:209"/>
      <state state_ref="oval:org.mitre.oval:ste:207"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:208" version="1" check="at least one" comment="Patch 118954-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:208"/>
      <state state_ref="oval:org.mitre.oval:ste:206"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:207" version="1" check="at least one" comment="Patch 109931-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:207"/>
      <state state_ref="oval:org.mitre.oval:ste:205"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:206" version="1" check="at least one" comment="Patch 109932-10 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:206"/>
      <state state_ref="oval:org.mitre.oval:ste:204"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:205" version="1" check="at least one" comment="Patch 114219-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:205"/>
      <state state_ref="oval:org.mitre.oval:ste:203"/>
    </patch_test>
    <package_test id="oval:org.mitre.oval:tst:204" version="1" check="at least one" comment="Pkg SUNWTiff is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:204"/>
    </package_test>
    <package_test id="oval:org.mitre.oval:tst:203" version="1" check="at least one" comment="Pkg SUNWTiffx is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:203"/>
    </package_test>
    <patch_test id="oval:org.mitre.oval:tst:202" version="1" check="at least one" comment="Patch 114220-11 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:202"/>
      <state state_ref="oval:org.mitre.oval:ste:202"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:201" version="1" check="at least one" comment="Patch 119900-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:201"/>
      <state state_ref="oval:org.mitre.oval:ste:201"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:200" version="1" check="at least one" comment="Patch 119901-01 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:200"/>
      <state state_ref="oval:org.mitre.oval:ste:200"/>
    </patch_test>
    <uname_test id="oval:org.mitre.oval:tst:3045" version="1" check="at least one" comment="Solaris 7 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2851"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:213" version="1" check="at least one" comment="Patch 111844-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:213"/>
      <state state_ref="oval:org.mitre.oval:ste:211"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:212" version="1" check="at least one" comment="Patch 111845-03 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:212"/>
      <state state_ref="oval:org.mitre.oval:ste:210"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:211" version="1" check="at least one" comment="Patch 112785-38 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:211"/>
      <state state_ref="oval:org.mitre.oval:ste:209"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:210" version="1" check="at least one" comment="Patch 112786-27 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:210"/>
      <state state_ref="oval:org.mitre.oval:ste:208"/>
    </patch_test>
    <process_test id="oval:org.mitre.oval:tst:654" version="1" check="at least one" comment="Apache running (httpd)" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:526"/>
    </process_test>
    <uname_test id="oval:org.mitre.oval:tst:3051" version="1" check="at least one" comment="Solaris 9 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2857"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:2465" version="1" check="at least one" comment="sparc architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2309"/>
    </uname_test>
    <uname_test id="oval:org.mitre.oval:tst:2463" version="1" check="at least one" comment="ix86 architecture" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2307"/>
    </uname_test>
    <patch_test id="oval:org.mitre.oval:tst:217" version="1" check="at least one" comment="Patch 116973-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:217"/>
      <state state_ref="oval:org.mitre.oval:ste:215"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:216" version="1" check="at least one" comment="Patch 116974-02 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:216"/>
      <state state_ref="oval:org.mitre.oval:ste:214"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:215" version="1" check="at least one" comment="Patch 113146-05 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:215"/>
      <state state_ref="oval:org.mitre.oval:ste:213"/>
    </patch_test>
    <patch_test id="oval:org.mitre.oval:tst:214" version="1" check="at least one" comment="Patch 114145-04 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:214"/>
      <state state_ref="oval:org.mitre.oval:ste:212"/>
    </patch_test>
    <registry_test id="oval:org.mitre.oval:tst:2437" version="1" check="at least one" comment="Win2K/XP/2003 is patched" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2282"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:218" version="1" check="at least one" comment="the version of kerberos.dll is less than 5.2.3790.347" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:218"/>
      <state state_ref="oval:org.mitre.oval:ste:216"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:219" version="1" check="at least one" comment="the version of kerberos.dll is less than 5.2.3790.2464" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:218"/>
      <state state_ref="oval:org.mitre.oval:ste:217"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:2861" version="1" check="at least one" comment="Red Hat Enterprise 3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:1414"/>
      <state state_ref="oval:org.mitre.oval:ste:2679"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:1381" version="1" check="at least one" comment="/usr/bin/cvs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:953"/>
      <state state_ref="oval:org.mitre.oval:ste:1243"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1380" version="1" check="at least one" comment="/usr/bin/cvs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:953"/>
      <state state_ref="oval:org.mitre.oval:ste:1242"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1379" version="1" check="at least one" comment="/usr/bin/cvs is executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:953"/>
      <state state_ref="oval:org.mitre.oval:ste:1241"/>
    </file_test>
    <rpminfo_test id="oval:org.mitre.oval:tst:1347" version="1" check="at least one" comment="cvs rpm version prior to 1.11.2-24 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <object object_ref="oval:org.mitre.oval:obj:933"/>
      <state state_ref="oval:org.mitre.oval:ste:1209"/>
    </rpminfo_test>
    <file_test id="oval:org.mitre.oval:tst:220" version="1" check="at least one" comment="the version of kerberos.dll is less than 5.1.2600.2698" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:218"/>
      <state state_ref="oval:org.mitre.oval:ste:218"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:221" version="1" check="at least one" comment="the version of kerberos.dll is less than 5.1.2600.1701" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:218"/>
      <state state_ref="oval:org.mitre.oval:ste:219"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3085" version="1" check="at least one" comment="Windows 2000 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:419"/>
      <state state_ref="oval:org.mitre.oval:ste:2890"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3084" version="1" check="at least one" comment="Win2K/XP/2003 service pack 4 (or later) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2889"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:222" version="1" check="at least one" comment="the version of kerberos.dll is less than 5.0.2195.7053" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:218"/>
      <state state_ref="oval:org.mitre.oval:ste:220"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:223" version="1" check="at least one" comment="the version of rdpwd.sys is less than 5.2.3790.2465" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:220"/>
      <state state_ref="oval:org.mitre.oval:ste:221"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:224" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.2.3790.2483" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:222"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:3019" version="1" check="at least one" comment="Win2K/XP/2003 service pack 2 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2827"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:225" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.1.2600.2716" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:223"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:226" version="1" check="at least one" comment="the version of tapisrv.dll is less than 5.1.2600.1715" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:221"/>
      <state state_ref="oval:org.mitre.oval:ste:224"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2761" version="1" check="at least one" comment="Windows Server 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:419"/>
      <state state_ref="oval:org.mitre.oval:ste:2582"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:227" version="1" check="at least one" comment="the version of mshtml.dll is less than 6.0.3790.2491" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:222"/>
      <state state_ref="oval:org.mitre.oval:ste:225"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:228" version="1" check="at least one" comment="the version of spoolsv.exe is less than 5.1.2600.1699" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:223"/>
      <state state_ref="oval:org.mitre.oval:ste:226"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:229" version="1" check="at least one" comment="the version of umpnpmgr.dll is less than 5.2.3790.2477" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:224"/>
      <state state_ref="oval:org.mitre.oval:ste:227"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:233" version="1" check="at least one" comment="Firefox version 0.9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:231"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:232" version="1" check="at least one" comment="Mozilla Firefox version 0.9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:227"/>
      <state state_ref="oval:org.mitre.oval:ste:230"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:231" version="1" check="at least one" comment="Mozilla Thunderbird version 0.6-0.8 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:229"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:230" version="1" check="at least one" comment="Mozilla Thunderbird version 0.6-0.8 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:225"/>
      <state state_ref="oval:org.mitre.oval:ste:228"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:235" version="1" check="at least one" comment="Mozilla Suite version 1.7.4 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:233"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:234" version="1" check="at least one" comment="Mozilla Suite version 1.7.4 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:229"/>
      <state state_ref="oval:org.mitre.oval:ste:232"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:237" version="1" check="at least one" comment="Mozilla Thunderbird version 0.8 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:235"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:236" version="1" check="at least one" comment="Mozilla Thunderbird version 0.8 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:231"/>
      <state state_ref="oval:org.mitre.oval:ste:234"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:241" version="1" check="at least one" comment="Mozilla Thunderbird version 0.6-0.9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:239"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:240" version="1" check="at least one" comment="Mozilla Thunderbird version 0.6-0.9 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:233"/>
      <state state_ref="oval:org.mitre.oval:ste:238"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:239" version="1" check="at least one" comment="Mozilla Suite version 1.7-1.7.3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:237"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:238" version="1" check="at least one" comment="Mozilla Suite version 1.7-1.7.3 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:232"/>
      <state state_ref="oval:org.mitre.oval:ste:236"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:243" version="1" check="at least one" comment="Firefox version 0.9 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:241"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:242" version="1" check="at least one" comment="Mozilla Firefox version 0.9 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:234"/>
      <state state_ref="oval:org.mitre.oval:ste:240"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:245" version="1" check="at least one" comment="Firefox version 1.0 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:243"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:244" version="1" check="at least one" comment="Mozilla Firefox version 1.0 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:235"/>
      <state state_ref="oval:org.mitre.oval:ste:242"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:249" version="1" check="at least one" comment="Mozilla Thunderbird version 1.0 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:247"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:248" version="1" check="at least one" comment="Mozilla Thunderbird version 1.0 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:237"/>
      <state state_ref="oval:org.mitre.oval:ste:246"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:247" version="1" check="at least one" comment="Mozilla Suite version 1.7.5 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:245"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:246" version="1" check="at least one" comment="Mozilla Suite version 1.7.5 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:236"/>
      <state state_ref="oval:org.mitre.oval:ste:244"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:251" version="1" check="at least one" comment="Firefox version 1.0.1 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:249"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:250" version="1" check="at least one" comment="Mozilla Firefox version 1.0.1 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:238"/>
      <state state_ref="oval:org.mitre.oval:ste:248"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:253" version="1" check="at least one" comment="Mozilla Suite version 1.7.6 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:251"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:252" version="1" check="at least one" comment="Mozilla Suite version 1.7.6 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:239"/>
      <state state_ref="oval:org.mitre.oval:ste:250"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:255" version="1" check="at least one" comment="Mozilla Firefox version 1.0.3 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:241"/>
      <state state_ref="oval:org.mitre.oval:ste:253"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:254" version="1" check="at least one" comment="Mozilla Suite version 1.7.7 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:240"/>
      <state state_ref="oval:org.mitre.oval:ste:252"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:257" version="1" check="at least one" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:226"/>
      <state state_ref="oval:org.mitre.oval:ste:255"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:256" version="1" check="at least one" comment="Mozilla Thunderbird version 1.0.2 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:242"/>
      <state state_ref="oval:org.mitre.oval:ste:254"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:259" version="1" check="at least one" comment="Firefox version 1.0.2 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:257"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:258" version="1" check="at least one" comment="Mozilla Firefox version 1.0.2 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:243"/>
      <state state_ref="oval:org.mitre.oval:ste:256"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:263" version="1" check="at least one" comment="Firefox version 1.0.4 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:261"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:262" version="1" check="at least one" comment="Mozilla Firefox version 1.0.4 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:245"/>
      <state state_ref="oval:org.mitre.oval:ste:260"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:261" version="1" check="at least one" comment="Mozilla Suite version 1.7.8 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:259"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:260" version="1" check="at least one" comment="Mozilla Suite version 1.7.8 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:244"/>
      <state state_ref="oval:org.mitre.oval:ste:258"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:265" version="1" check="at least one" comment="Firefox version 1.0.3 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:228"/>
      <state state_ref="oval:org.mitre.oval:ste:263"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:264" version="2" check="at least one" comment="Mozilla Suite version 1.7.7 or earlier is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:230"/>
      <state state_ref="oval:org.mitre.oval:ste:262"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2838" version="1" check="at least one" comment="Windows XP is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:419"/>
      <state state_ref="oval:org.mitre.oval:ste:2657"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2748" version="1" check="at least one" comment="32-Bit version of Windows is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1576"/>
      <state state_ref="oval:org.mitre.oval:ste:2569"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1510" version="1" check="at least one" comment="the patch kb835732 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1015"/>
      <state state_ref="oval:org.mitre.oval:ste:1364"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1477" version="1" check="at least one" comment="the HCP Protocol is registered" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1001"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1333" version="1" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.128" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:922"/>
      <state state_ref="oval:org.mitre.oval:ste:1197"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1332" version="1" check="at least one" comment="the version of helpctr.exe is less than 5.1.2600.1340" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:922"/>
      <state state_ref="oval:org.mitre.oval:ste:1196"/>
    </file_test>
    <registry_test check="at least one" comment="Win2K/XP/2003 service pack 2 (or later) is installed" id="oval:org.mitre.oval:tst:2837" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2656"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2794" version="1" check="at least one" comment="Internet Explorer 5.01 Service Pack 4 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2614"/>
    </registry_test>
    <registry_test check="at least one" comment="Windows 2000 is installed" id="oval:org.mitre.oval:tst:2" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:123"/>
      <state state_ref="oval:org.mitre.oval:ste:2"/>
    </registry_test>
    <registry_test check="at least one" comment="SP4 or later Installed" id="oval:org.mitre.oval:tst:3073" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2878"/>
    </registry_test>
    <registry_test check="at least one" comment="Windows Server 2003 is installed" id="oval:org.mitre.oval:tst:4" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:123"/>
      <state state_ref="oval:org.mitre.oval:ste:4"/>
    </registry_test>
    <registry_test check="at least one" comment="a Win2K/XP/2003 service pack is installed" id="oval:org.mitre.oval:tst:2845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:93" version="1" check="at least one" comment="the version of vgx.dll is less than 6.0.2900.2997" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:308"/>
      <state state_ref="oval:org.mitre.oval:ste:47"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:25" version="1" check="at least one" comment="the version of vgx.dll is less than 6.0.2800.1580" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:308"/>
      <state state_ref="oval:org.mitre.oval:ste:66"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2333" version="1" check="at least one" comment="Internet Explorer 6 (any patch level) is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:247"/>
      <state state_ref="oval:org.mitre.oval:ste:2185"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:163" version="1" check="at least one" comment="the version of vgx.dll is less than 5.0.3845.1800" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:308"/>
      <state state_ref="oval:org.mitre.oval:ste:45"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:124" version="1" check="at least one" comment="the version of vgx.dll is less than 6.0.3790.593" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:308"/>
      <state state_ref="oval:org.mitre.oval:ste:8"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:10" version="1" check="at least one" comment="the version of vgx.dll is less than 6.0.3790.2794" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:308"/>
      <state state_ref="oval:org.mitre.oval:ste:179"/>
    </file_test>
    <uname_test id="oval:org.mitre.oval:tst:3145" version="1" check="at least one" comment="Solaris 8 Installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:679"/>
      <state state_ref="oval:org.mitre.oval:ste:2941"/>
    </uname_test>
    <file_test id="oval:org.mitre.oval:tst:3130" version="1" check="at least one" comment="File xlock exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1779"/>
    </file_test>
    <patch_test id="oval:org.mitre.oval:tst:3129" version="1" check="at least one" comment="Patch 108652-38 or later installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <object object_ref="oval:org.mitre.oval:obj:876"/>
      <state state_ref="oval:org.mitre.oval:ste:2930"/>
    </patch_test>
    <file_test id="oval:org.mitre.oval:tst:3128" version="1" check="at least one" comment="File xlock SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1779"/>
      <state state_ref="oval:org.mitre.oval:ste:2929"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:3127" version="1" check="at least one" comment="File xlock SUID and executable" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <object object_ref="oval:org.mitre.oval:obj:1779"/>
      <state state_ref="oval:org.mitre.oval:ste:2928"/>
    </file_test>
    <family_test check="only one" comment="the installed operating system is part of the Microsoft Windows family" id="oval:org.mitre.oval:tst:99" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <object object_ref="oval:org.mitre.oval:obj:99"/>
      <state state_ref="oval:org.mitre.oval:ste:99"/>
    </family_test>
    <registry_test check="at least one" comment="Windows XP is installed" id="oval:org.mitre.oval:tst:3" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:123"/>
      <state state_ref="oval:org.mitre.oval:ste:3"/>
    </registry_test>
    <registry_test check="at least one" comment="Win2K/XP/2003 service pack 1 is installed" id="oval:org.mitre.oval:tst:2843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:717"/>
      <state state_ref="oval:org.mitre.oval:ste:2662"/>
    </registry_test>
    <registry_test check="at least one" comment="64-Bit version of Windows is installed" id="oval:org.mitre.oval:tst:2747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1576"/>
      <state state_ref="oval:org.mitre.oval:ste:2568"/>
    </registry_test>
  </tests>
  <objects>
    <registry_object id="oval:org.mitre.oval:obj:1078" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetShow</key>
      <name>Version</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:248"/>
      <filename>nscm.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1076" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:248"/>
      <filename>nspmon.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
      <name>IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\nsstation</key>
      <name>Start</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1073" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Updates\Windows Media Services\KB832359</key>
      <name>Start</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1361" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
      <name operation="equals">SharePoint</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:52" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Wmvcore.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:6" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\MediaPlayer\PlayerUpgrade</key>
      <name>PlayerVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:210"/>
      <filename>exprox.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1480" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\832759</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\MSExchangeWEB\DAV</key>
      <name operation="equals">ReuseConnections</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:831"/>
      <filename>aspnet_filter.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:5" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:112"/>
      <filename>nwrdr.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:7" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\TFTPD\Parameters</key>
      <name>Masters</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:93" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\TFTPD</key>
      <name xsi:nil="true"/>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113073</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:375" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWlvmr</pkginst>
    </package_object>
    <file_object id="oval:org.mitre.oval:obj:374" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="pattern match">/etc/rc[2-4].d</path>
      <filename>S[0-9][0-9]svm.init</filename>
    </file_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:373" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc</path>
      <filename>vfstab</filename>
      <line operation="pattern match">^/dev/md/</line>
    </textfilecontent_object>
    <registry_object id="oval:org.mitre.oval:obj:8" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\VisualStudio\8.0</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:38" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:443"/>
      <filename>WmiScriptUtils.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q841373</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <metabase_object id="oval:org.mitre.oval:obj:495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="pattern match">LM\\W3SVC\\/d*\\ROOT</key>
      <id datatype="int" operation="equals">6011</id>
    </metabase_object>
    <registry_object id="oval:org.mitre.oval:obj:494" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">System\CurrentControlSet\Services\w3svc\parameters</key>
      <name operation="equals">MaxClientRequestBufferData</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:633" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Ntkrnlpa.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/dt/bin</path>
      <filename>dtlogin</filename>
    </file_object>
    <process_object id="oval:org.mitre.oval:obj:702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*dtlogin.*</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:701" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108919</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112807</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107180</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWadmfw</pkginst>
    </package_object>
    <inetd_object id="oval:org.mitre.oval:obj:751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/sbin/sadmind</service_name>
    </inetd_object>
    <patch_object id="oval:org.mitre.oval:obj:750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116457</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116442</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116454</base>
    </patch_object>
    <inetd_object id="oval:org.mitre.oval:obj:747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/sbin/sadmind</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:17" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:224"/>
      <filename>Flash9.ocx</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:80" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:224"/>
      <filename>Flash8.ocx</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:885" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\VERITAS\Backup Exec\Server</key>
      <name operation="equals">CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:884" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Control\LSA</key>
      <name operation="equals">RestrictAnonymous</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:427" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112604</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112609</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">115172</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="pattern match">/etc</path>
      <filename>hostname6?\.le.*</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="not equal">109007</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:806" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:241"/>
      <filename>CrystalDecisions.Web.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:805" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\w3svc</key>
      <name operation="equals">Start</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:925" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118908</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match">.*Xorg\b.*</command>
    </process_object>
    <file_object id="oval:org.mitre.oval:obj:929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/proc/tty/driver</path>
      <filename>serial</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:928" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/proc/tty/driver</path>
      <filename/>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:927" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/proc/tty</path>
      <filename/>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:926" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/proc</path>
      <filename/>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:932" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:245"/>
      <filename>vserver.vxd</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:931" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\UtilMan{5c773859-bb96- 48fa-875b-6a58aae072f4}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:936" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.CORE2-KRN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:935" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHKL_33713</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:934" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHKL_33714</patch_name>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:937" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>krb5-libs</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:940" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal-gnome</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:942" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>squid</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:941" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <registry_object id="oval:org.mitre.oval:obj:1685" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes</key>
      <name operation="equals">gopher</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:944" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>utempter</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/sbin</path>
      <filename>utempter</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:946" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>lha</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>lha</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:948" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tcpdump</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:952" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:951" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:950" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:949" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:954" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cvs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:958" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msjet40.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:957" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wmsjet40.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:956" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837001</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:959" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>rsync</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:963" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ImageMagick</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1A02</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1689" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1A02</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1A03</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1687" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1A03</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:972" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kdelibs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:971" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/kerberos/bin</path>
      <filename>telnet</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:970" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>rlogin</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:969" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/kerberos/bin</path>
      <filename>rlogin</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:968" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ssh</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>kmail</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:975" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ipsec-tools</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:974" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">UDP</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <patch_object id="oval:org.mitre.oval:obj:1996" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112785</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119059</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1927" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>Xprt</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:2024" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119060</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112786</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">108652</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2007" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">108653</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:2350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>Xsun</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>squid</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:977" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/bin</path>
      <filename>mount</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:980" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:979" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-hugemem</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:960" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>nsiislog.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:982" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB817772</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822343</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:985" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\Hotfix\Q811114</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:987" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>code.asp</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:986" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q232449</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:995" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\Microsoft\Active Setup\Installed Components\{A954CDD5-A95F-414F-B3FE-FBEF9D2AECEA}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:996" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mozilla-nss</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:998" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Msw3prt.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:997" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>w3svc.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:961" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>h323.tsp</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q291845</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wintrust.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q311967</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1013" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1012" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal-gnome</name>
    </rpminfo_object>
    <patch_object id="oval:org.mitre.oval:obj:1021" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118535</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1020" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121004</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1019" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109325</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1018" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118536</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1017" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121005</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1026" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1025" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal-gnome</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1022" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>tethereal</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1028" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>squid</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1027" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mod_ssl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mozilla</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1032" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mozilla-nss</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1036" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1035" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1034" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-perl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1033" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl096b</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1038" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>net-snmp</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1037" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1041" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1040" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-bigmem</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1043" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cvs</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kdepim</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1045" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>httpd</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>httpd</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1047" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sysstat</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>nfs-utils</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1052" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1051" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1050" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-bigmem</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1054" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kdepim</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1053" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/share/services</path>
      <filename>kfile_vcf.desktop</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1057" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1056" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal=gnome</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1024" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ethereal</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1023" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/sbin</path>
      <filename>ethereal</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1055" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/sbin</path>
      <filename>tethereal</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1059" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cvs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1058" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/</path>
      <filename xsi:nil="true"/>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1060" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tcpdump</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1061" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sysstat</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1062" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>tcpdump</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:947" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/sbin</path>
      <filename>tcpdump</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1065" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdk-pixbuf</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1064" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdk-pixbuf-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1063" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdk-pixbuf-gnome</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1068" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdk-pixbuf</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdk-pixbuf-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdk-pixbuf-gnome</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1069" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:246"/>
      <filename>msgsc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1072" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
      <name operation="pattern match">.*</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1071" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1070" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:247"/>
      <filename>utlook.exe</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1079" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mutt</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1082" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1081" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1080" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-bigmem</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1085" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libxml2</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1084" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libxml2-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1083" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libxml2-python</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>XFree86</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1088" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mod_python</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1087" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">TCP</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1089" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>samba</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pwlib</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1093" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1092" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1091" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-hugemem</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1094" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kdelibs</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1096" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mc</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mc</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1098" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>slocate</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>slocate</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>ssmsrp70.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>dbmsrpcn.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gaim</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mailman</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mutt</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>netpbm</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>netpbm-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>netpbm-progs</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>XFree86</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/X11R6/bin</path>
      <filename>XFree86</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1336" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>netpbm</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1335" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>netpbm-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>netpbm-progs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1333" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>411toppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1332" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>asciitopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1331" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>atktopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1330" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>bioradtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1329" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>bmptoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1328" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>brushtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1327" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>cmuwmtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1326" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>eyuvtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1325" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>fiascotopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1324" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>fitstopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1323" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>fstopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1322" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>g3topbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1321" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gemtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1320" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gemtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1319" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>giftopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1318" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gouldtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1317" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>hipstopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1316" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>hpcdtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1315" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>icontopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1314" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ilbmtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1313" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>imgtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1312" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>jpegtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1311" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>leaftoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1310" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>lispmtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1309" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>macptopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1308" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mdatopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1307" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mgrtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1306" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mtvtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1305" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>neotoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1304" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>palmtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1303" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamchannel</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1302" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamcut</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1301" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamdeinterlace</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1300" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamfile</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1299" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamoil</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1298" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamstretch</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pamtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmclean</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmlife</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmmake</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1293" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmmask</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1292" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmpage</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1291" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmpscale</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmreduce</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1289" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtext</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1288" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmto10x</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1287" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmto4425</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1286" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoascii</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1285" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoatk</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1284" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtobbnbg</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1283" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtocmuwm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1282" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoepsi</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1281" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoepson</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1280" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtog3</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1279" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtogem</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1278" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtogo</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1277" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoicon</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1276" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtolj</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1275" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoln03</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtolps</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1273" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtomacp</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1272" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtomda</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1271" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtomgr</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1270" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtonokia</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1268" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtopi3</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtopk</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1266" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoplot</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1265" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoppa</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1264" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtopsg3</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1263" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoptx</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1262" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtowbmp</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1261" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtox10bm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoxbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtoybm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1258" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmtozinc</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1257" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pbmupc</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1256" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pcxtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1255" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmbentley</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1254" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmcrater</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1253" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmedge</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1252" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmenhance</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1251" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmhist</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1250" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmkernel</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmnoise</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmnorm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1247" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmoil</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmramp</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1245" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmslice</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1244" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmtexture</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmtofs</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmtolispm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1241" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1240" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pgmtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pi1toppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1238" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pi3topbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pjtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1236" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pktopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1235" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pngtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1234" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmalias</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmarith</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1232" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmcat</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1231" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmcolormap</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmcomp</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1229" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmconvol</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmcrop</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmcut</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmdepth</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmenlarge</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmfile</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1223" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmflip</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmgamma</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmhisteq</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmhistmap</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnminterp</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnminvert</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmmontage</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmnlfilt</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1215" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmnoraw</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmpad</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1213" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmpaste</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1212" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmpsnr</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1211" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmremap</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmrotate</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmscale</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopict</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopj</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1206" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopjxl</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopuzz</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1204" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtorgb3</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtosixel</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtotga</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtouil</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtowinicon</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1199" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoxpm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1198" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoyuv</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1197" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoyuvsplit</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtv</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1195" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>psidtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pstopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>qrttoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1192" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>rasttopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>rawtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>rawtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>rgb3toppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>rletopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1187" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>sbigtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>sgitopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1185" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>sirtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1184" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>sldtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1183" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>spctoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1182" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>spottopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>sputoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>tgatoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1179" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>thinkjettopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1178" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>tifftopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1177" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>wbmptopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>winicontoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1175" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>xbmtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1174" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ximtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1173" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>xpmtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>xvminitoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1171" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>xwdtopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ybmtopbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>yuvsplittoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>yuvtoppm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>zeisstopnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmscalefixed</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmshear</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmsmooth</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmsplit</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtile</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtoddif</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1160" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtofiasco</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtofits</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtojpeg</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1157" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtopalm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtoplainpnm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtopng</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtops</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtorast</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtorle</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtosgi</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtosir</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1149" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtotiff</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtotiffcmyk</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pnmtoxwd</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1146" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppm3d</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmbrighten</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmchange</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmcie</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1142" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmcolormask</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmcolors</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmdim</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmdist</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmdither</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1137" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmflash</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmforge</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1135" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmhist</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1134" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmlabel</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1133" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmmake</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1132" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmmix</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1131" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmnorm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmntsc</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmpat</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1128" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmquant</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1127" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmqvga</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmrelief</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1125" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmshift</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1124" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmspread</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1123" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoacad</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtobmp</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1121" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoeyuv</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtogif</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1119" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoicr</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoilbm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtojpeg</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1116" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoleaf</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtolj</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1114" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtomitsu</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtompeg</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtoneo</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopcx</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopgm</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ppmtopi1</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pwlib</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="equals">1720</local_port>
    </inetlisteningservers_object>
    <patch_object id="oval:org.mitre.oval:obj:1699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112846</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_29269</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_30275</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_32181</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1346" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Microsoft Services for UNIX\KB896428</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1345" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Services for UNIX</key>
      <name operation="equals">Current_Release</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832483</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:1356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1355" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1354" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1353" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:1352" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_23947</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33790</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2616" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120955</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">106934</base>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist operation="pattern match">Perl5.*\.PERL-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist operation="pattern match">Perl5.*\.PERL-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1863" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist operation="pattern match">Perl5.*\.PERL-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist operation="pattern match">Perl5.*\.PERL-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist operation="pattern match">Perl5.*\.PERL-RUN</swlist>
    </swlist_object>
    <file_object id="oval:org.mitre.oval:obj:1366" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Imekr70.ime</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:2655" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWkrgdo</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:2213" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWkr5sv</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:2138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWkrggl</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:2617" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWkr5sl</pkginst>
    </package_object>
    <file_object id="oval:org.mitre.oval:obj:139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>dnsapi.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1369" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gftp</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1368" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gftp</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1371" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ImageMagick</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1373" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB830352</key>
      <name>Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112234</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1375" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">117172</base>
    </patch_object>
    <inetd_object id="oval:org.mitre.oval:obj:1704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/dt/bin/dtspcd</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/dt/bin</path>
      <filename>dtspcd</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:363"/>
      <filename>vbe6.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1382" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>winsrv.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1381" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q328310</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108721</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>rh-postgresql-server</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1389" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \((0\..*|1\.0\..*\))</key>
      <name>DisplayName</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110453</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1391" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ypserv</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1390" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1393" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>xpdf</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1392" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>xpdf</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1398" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109321</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1397" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114890</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120467</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1395" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120468</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1394" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/etc/lp/printers</path>
      <filename>*</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1400" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>xinetd</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1399" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <registry_object id="oval:org.mitre.oval:obj:1401" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828028</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1787" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>kcms_configure</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1403" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_30983</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1402" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_31732</patch_name>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1406" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mikmod</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mikmod</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:1412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1411" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-UTIL</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-ADMIN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-LIB</swlist>
    </swlist_object>
    <file_object id="oval:org.mitre.oval:obj:194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>mmc.exe</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>vsftpd</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">TCP</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1419" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>up2date</name>
    </rpminfo_object>
    <process_object id="oval:org.mitre.oval:obj:1418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*rhnsd.*$</command>
    </process_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1421" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sysreport</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/lib/snmp</path>
      <filename>mibiisa</filename>
    </file_object>
    <process_object id="oval:org.mitre.oval:obj:1712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*mibiisa.*</command>
    </process_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>unzip</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>unzip</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:2784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_29964</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1856" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_28848</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>WUFTP-26.INETSVCS-FTP</swlist>
    </swlist_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>squirrelmail</name>
    </rpminfo_object>
    <patch_object id="oval:org.mitre.oval:obj:2358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_23261</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:1876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.C2400-UTIL</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ADMN-ENG-A-MAN</swlist>
    </swlist_object>
    <registry_object id="oval:org.mitre.oval:obj:1716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Ras\CurrentVersion</key>
      <name operation="equals">PathName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>rasman.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1715" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318138</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1789" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cups</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <swlist_object id="oval:org.mitre.oval:obj:1431" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>X11.X11-RUN-CL</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:1430" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_32109</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1429" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_30791</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1428" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_33589</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1427" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_31833</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_32366</patch_name>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1433" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sendmail</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1432" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1434" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sendmail</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1435" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
      <name>DisplayVersion</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:2115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:1815" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33414</patch_name>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:1441" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWrcmds</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:1440" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">118239</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1439" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116984</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1438" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">117455</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:1437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="equals" datatype="string">/usr/sbin/in.rwhod</command>
    </process_object>
    <registry_object id="oval:org.mitre.oval:obj:1442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\Setup Packages</key>
      <name operation="equals">FrontPage 2000 Server Extensions SR</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Publisher\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:2163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Mspub.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:94" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:297"/>
      <filename>mspub.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q331953</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1447" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828749</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1452" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sendmail</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1451" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/sbin</path>
      <filename>sendmail.sendmail</filename>
    </file_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">TCP</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1456" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>wl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>wl-xemacs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1454" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>emacs</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1453" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>xemacs</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>samba</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <patch_object id="oval:org.mitre.oval:obj:1720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">111596</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:1459" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWxwplt</pkginst>
    </package_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1462" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>samba</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1461" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">TCP</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>Query.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1463" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB832894</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1351" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>sqlsrv32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1464" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\DataAccess\Q832483</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1466" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>postfix</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1465" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>eog</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>eog</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:258" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWdthep</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:257" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107178</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:256" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108949</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:255" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116308</base>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2556" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>TOUR_PRODUCT.T-NET2-KRN</swlist>
    </swlist_object>
    <registry_object id="oval:org.mitre.oval:obj:251" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883935</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\RasMan</key>
      <name operation="equals">Start</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pine</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1467" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>pine</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\.NETFramework\policy\v1.0</key>
      <name operation="equals"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:266" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\NET Framework Setup\1.0\M886905</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:265" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Microsoft\Active Setup\Installed Components\{78705f0d-e8db-4b2d-8193-982bdda15ecd}</key>
      <name operation="equals">Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:264" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{78705f0d-e8db-4b2d-8193-982bdda15ecd}</key>
      <name operation="equals">Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:262" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.0\M886906</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:268" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\Tcpip\Parameters</key>
      <name>SynAttackProtect</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ABEB838C-A1A7-4C5D-B7E1-8B4314600208}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:160" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>netapi32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:272" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Proxy Server</key>
      <name operation="equals">Microsoft Proxy Server</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:271" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:205"/>
      <filename>w3proxy.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:270" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888258</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>php</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:249"/>
      <filename>sqlisapi.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112960</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:273" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc</path>
      <filename>nsswitch.conf</filename>
      <line operation="pattern match">^[^#].*_attr.*ldap</line>
    </textfilecontent_object>
    <file_object id="oval:org.mitre.oval:obj:1473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>ssinc.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1726" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>^(/usr)?/bin</path>
      <filename>admintool$</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Fpc</key>
      <name>InstallDirectory</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:250"/>
      <filename>323fltr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1476" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\291</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1475" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Fpc\\Arrays\\\{[^\\]+\}\\Extensions\\Proxy-Plugins\\\{FE440D49-AB26-11D2-A101-00C04FB6CFB6\}$</key>
      <name operation="equals">msFPCEnabled</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1379" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:239"/>
      <filename>mswrd6.wpc</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:282" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB873339\ Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108827</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108901</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:286" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108451</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:285" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113319</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:284" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">11233</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:287" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB893086\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>perl-CGI</name>
    </rpminfo_object>
    <patch_object id="oval:org.mitre.oval:obj:1727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">111826</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1483" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>pam_smb</name>
    </rpminfo_object>
    <process_object id="oval:org.mitre.oval:obj:288" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">.*krb5kdc.*</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:2218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118822</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-perl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1489" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl096</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl096b</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:41" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>Rmcast.sys</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1494" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>sp3res.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB822679</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssh-server</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1500" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssh-server</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <patch_object id="oval:org.mitre.oval:obj:295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110057</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110060</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:293" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116462</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>nfs-utils</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <registry_object id="oval:org.mitre.oval:obj:1730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q269862</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:261" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>mqrt.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:299" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB892944</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:298" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\MSMQ</key>
      <name operation="equals"/>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:1871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>WUFTP-26.INETSVCS-FTP</swlist>
    </swlist_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1504" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mysql-server</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mutt</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1505" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mutt</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:303" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\VisualStudio\7.0</key>
      <name xsi:nil="true"/>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>lv</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Common\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:252"/>
      <filename>sohev.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:250" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:202"/>
      <filename>zipfldr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Publisher\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:39" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Fpc</key>
      <name>InstallDirectory</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:306" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:208"/>
      <filename>msphlpr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:305" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\408</key>
      <name operation="equals">Kbs</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>tlntsvr.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q307298</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\Tlntsvr</key>
      <name operation="equals">Start</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>lprng</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/libexec/filters</path>
      <filename>psbanner</filename>
    </file_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <patch_object id="oval:org.mitre.oval:obj:2341" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33412</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <file_object id="oval:org.mitre.oval:obj:1786" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/lib/dmi</path>
      <filename>dmispd</filename>
    </file_object>
    <inetd_object id="oval:org.mitre.oval:obj:1783" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/dt/bin/rpc.cmsd</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/dt/bin</path>
      <filename>rpc.cmsd</filename>
    </file_object>
    <process_object id="oval:org.mitre.oval:obj:1780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*dmispd.*</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:1732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108541</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:310" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc</path>
      <filename>nsswitch.conf</filename>
      <line operation="pattern match">^[^#]*hosts:.*dns</line>
    </textfilecontent_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1521" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kdelibs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>konqueror</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:2051" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_34077</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:1735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112899</base>
    </patch_object>
    <inetd_object id="oval:org.mitre.oval:obj:1734" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/lib/netsvc/rwall/rpc.rwalld</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/lib/netsvc/rwall</path>
      <filename>rpc.rwalld</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:319" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWpcr</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:318" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWpcu</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:317" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWpsr</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:316" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWpsu</pkginst>
    </package_object>
    <file_object id="oval:org.mitre.oval:obj:1526" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:253"/>
      <filename>w3proxy.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server</key>
      <name>InstallationLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1524" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:253"/>
      <filename>wspsrv.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\257</key>
      <name operation="equals">Kbs</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\Fwsrv</key>
      <name operation="equals">Start</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:325" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108574</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:324" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108162</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:323" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108416</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:321" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110898</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:320" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109324</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:330" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\9161A261-6ABE-4668-BBFA-AD06B3F642CF</key>
      <name operation="equals">Microsoft Exchange</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:328" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:210"/>
      <filename>xlsasink.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:327" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Exchange Server 2003\SP1\KB894549</key>
      <name operation="pattern match">.*</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:333" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109613</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:332" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112810</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:331" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWdtdst</pkginst>
    </package_object>
    <registry_object id="oval:org.mitre.oval:obj:337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix \KB873339\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1830" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112238</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:2551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWCryr</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:2709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112390</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2466" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112237</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2128" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120469</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112240</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112537</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120470</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1847" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112536</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:2361" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWCry</pkginst>
    </package_object>
    <file_object id="oval:org.mitre.oval:obj:338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/etc</path>
      <filename>named.conf</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWntpu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109409</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:341" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109667</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:340" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="equals" datatype="string">/usr/lib/inet/xntpd</command>
    </process_object>
    <file_object id="oval:org.mitre.oval:obj:344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:202"/>
      <filename>shell32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:345" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0150048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1736" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q318593</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:4" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:998"/>
      <filename>System.web.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1340" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923-IE6SP1-20050225.103456</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1532" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>hhsetup.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323255</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>asp.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:254"/>
      <filename>fp5areg.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:254"/>
      <filename>fp30reg.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\5.0\Setup Packages</key>
      <name operation="equals">Microsoft FrontPage Server Extensions 2002</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:349" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:348" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:347" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng10-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:346" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libpng10</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:255"/>
      <filename>fp4areg.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1536" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:255"/>
      <filename>fp30reg.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:354" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">106950</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:353" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109147</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:352" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112963</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120954</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:2033" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWamsvc</pkginst>
    </package_object>
    <file_object id="oval:org.mitre.oval:obj:357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>webvw.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP5\KB894320\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:355" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced</key>
      <name operation="equals">WebView</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cpio</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/bin</path>
      <filename>cpio</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:361" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114332</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:360" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc</path>
      <filename>system</filename>
      <line operation="pattern match">^[^\*]*set.*c2audit.*</line>
    </textfilecontent_object>
    <registry_object id="oval:org.mitre.oval:obj:365" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\.NETFramework\policy\v1.1</key>
      <name operation="equals"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:364" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals"/>
      <name operation="equals">Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:363" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.1\M886903</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:263" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:204"/>
      <filename>System.web.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\.NETFramework Setup\1.1\M886904</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:2749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ARRAY-MGMT</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ADMN-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:2516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_23262</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ARRAY-MGMT</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2293" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ADMN-ENG-A-MAN</swlist>
    </swlist_object>
    <package_object id="oval:org.mitre.oval:obj:368" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWsshdu</pkginst>
    </package_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:366" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc/ssh</path>
      <filename>sshd_config</filename>
      <line operation="pattern match">^[^#]*ListenAddress.*0\.0\.0\.0</line>
    </textfilecontent_object>
    <file_object id="oval:org.mitre.oval:obj:1540" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/etc/httpd/conf.d</path>
      <filename>php.conf</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:369" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q890175</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824245</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:372" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP1\KB824105\Filelist</key>
      <name operation="equals">installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:371" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB824105\Filelist</key>
      <name operation="equals">installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:370" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>netbt.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1522" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB893086\ Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>php</name>
    </rpminfo_object>
    <package_object id="oval:org.mitre.oval:obj:383" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWbip</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:382" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">118313</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:381" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116986</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116774</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="pattern match">^/usr/sbin/sparcv.</path>
      <filename>whodo$</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">111600</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>^/usr/sbin/sparcv.</path>
      <filename>whodo</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:22" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Comctl32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q303984</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:387" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6000-11D3-8CFE-0150048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:386" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:214"/>
      <filename>GDIPLUS.DLL</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:388" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\9040110900063D11C8EF10054038389C\Patches\9FEC06657760FC84499ED532196D45EE2</key>
      <name operation="equals">Security Update for Office 2003: Wordperfect 5.x Converter (KB873378)</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\lanmanworkstation</key>
      <name operation="equals">Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>netdde.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:202"/>
      <filename>netdde.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>nddenb32.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:202"/>
      <filename>nddenb32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Media Player\wm817787</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823803</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>impprov.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:392" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB873339\ Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_30302</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_30006</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\.NETFramework\policy\v2.0</key>
      <name xsi:nil="true"/>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1686" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110896</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114008</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:394" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB821557</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:256"/>
      <filename>shtml.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1554" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB810217</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1553" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
      <name operation="equals">fp_extensions</name>
    </registry_object>
    <metabase_object id="oval:org.mitre.oval:obj:1552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="equals">LM\W3SVC</key>
      <id datatype="int" operation="equals">6014</id>
    </metabase_object>
    <package_object id="oval:org.mitre.oval:obj:396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="pattern match" datatype="string">SUNWdtba[sx]</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:395" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108219</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1556" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313450</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:257"/>
      <filename>sgprox.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:257"/>
      <filename>eplrec.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:257"/>
      <filename>qlvdi.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:401" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">116895</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:400" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">117000</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119255</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119254</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823980</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
      <name operation="equals">VersionMax</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
      <name operation="equals">VersionMin</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:403" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Adobe\Acrobat Reader\6.0\Installer</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:402" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:216"/>
      <filename>eBook.api</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\MSSQLServer\MSSQLServer</key>
      <name operation="equals">LoginMode</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows 2000\SP4\Q321599</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Media Player\wm308567</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-hugemem</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <package_object id="oval:org.mitre.oval:obj:412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWxwfs</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:411" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113923</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1568" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>dxmasf.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msdxm.ocx</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wmpcore.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1547" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:229"/>
      <filename>wmplayer.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Media Player\wm320920</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ddskk</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ddskk-xemacs</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329170</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\lanmanserver\parameters</key>
      <name operation="equals">enablesecuritysignature</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:413" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
      <name operation="equals">WindowsInstaller</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329414</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:367" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113273</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:415" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*sshd.*</command>
    </process_object>
    <registry_object id="oval:org.mitre.oval:obj:417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:217"/>
      <filename>DIPLUS.DLL</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:242"/>
      <filename>Tcpip6.sys</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:218"/>
      <filename>MSCONV97.DLL</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:422" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Patches\A1334AC428B43BF4E9547C55D3DFE977</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:421" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00000409-78E1-11D2-B60F-006097C998E7}</key>
      <name operation="equals">DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00010409-78E1-11D2-B60F-006097C998E7}</key>
      <name operation="equals">DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:2113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
      <name>PROCESSOR_ARCHITECTURE</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1573" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gaim</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gaim</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:429" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114796</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:428" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWkcl2r</pkginst>
    </package_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326886</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:433" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="pattern match" datatype="string">SUNWkcsr[tx]</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:432" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114636</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:431" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107337</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:430" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">111400</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:439" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113505</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:438" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113508</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">115054</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">115055</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:435" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWscvw</pkginst>
    </package_object>
    <process_object id="oval:org.mitre.oval:obj:434" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^/usr/apache/bin/httpd.*SUNWscvw/conf/httpd.conf.*</command>
    </process_object>
    <registry_object id="oval:org.mitre.oval:obj:1370" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888113</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:277" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>llssrv.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885834</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\LicenseService</key>
      <name>Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:2550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:26"/>
      <filename>spoolsv.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:440" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB890923 \Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:2563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/etc</path>
      <filename>pam.conf</filename>
      <line operation="pattern match">[^#]*pam_krb5.+debug.*/etc/pam\.conf.*</line>
    </textfilecontent_object>
    <patch_object id="oval:org.mitre.oval:obj:2309" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112908</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:2143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/etc/krb5</path>
      <filename>krb5.conf</filename>
      <line operation="pattern match">[^(#|_)]*default_realm[^_]*</line>
    </textfilecontent_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:1866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/etc</path>
      <filename>syslog.conf</filename>
      <line operation="pattern match">[^#]*(debug|daemon\.debug).*/etc/syslog\.conf</line>
    </textfilecontent_object>
    <patch_object id="oval:org.mitre.oval:obj:1845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">115168</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1579" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:441" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp4-20040929.111451</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWkrbr</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="pattern match" datatype="string">SUNWkrbux?</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112925</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112923</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112921</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1580" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\Q305601</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:451" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873350</key>
      <name operation="equals">File</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:454" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Sp3res.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:453" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Umandlg.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:452" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB842526</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1582" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>krb5-libs</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>krb5-workstation</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:252" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>nntpsvc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB883935</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1583" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\NntpSvc</key>
      <name>Start</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:456" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP2\KB871250\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:462" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWypu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:461" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109328</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:460" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113579</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:459" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*ypxfrd.*</command>
    </process_object>
    <file_object id="oval:org.mitre.oval:obj:463" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:202"/>
      <filename>dplayx.dll</filename>
    </file_object>
    <metabase_object id="oval:org.mitre.oval:obj:1753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="pattern match">^LM\\MSFTPSVC\\.*$</key>
      <id datatype="int" operation="equals">1016</id>
    </metabase_object>
    <registry_object id="oval:org.mitre.oval:obj:158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Publisher\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>tshoot.ocx</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB826232</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>console.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>dbmslpcn.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>sqlmap70.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1594" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>sqlrepss.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>ssmslpcn.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1592" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>ssnmpn70.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>ums.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>msgprox.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Microsoft SQL Server\80</key>
      <name>SharedCode</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1589" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:257"/>
      <filename>eplprov.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1588" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>replrec.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>sqlvdi.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:466" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1377" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90110409-6000-11D3-8CFE-0150048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Dhcpcsvc.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>smtpsvc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:378" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885881</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\SMTPSVC</key>
      <name operation="equals">Start</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Exchange\Setup</key>
      <name operation="equals">Services Version</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>krb5-server</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:397" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>srvsvc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB888302</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:304" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Dhcpssvc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885249</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C3A6819F-62D3-4750-AF1C-28206DDF2C2E}</key>
      <name>Windows Messenger 5.1</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:220"/>
      <filename>Messengermsmsgs.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SSOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923 -ie501sp4-20050225.100310</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108748</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108752</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:291" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">106541</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">106942</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:483" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107477</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108551</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108754</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108756</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108758</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108760</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108762</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:476" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108764</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:475" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">.*rpcbind.*</command>
    </process_object>
    <package_object id="oval:org.mitre.oval:obj:489" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWsndmu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:351" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107684</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110615</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">.*sendmail .*</command>
    </process_object>
    <file_object id="oval:org.mitre.oval:obj:398" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:214"/>
      <filename>MSO.DLL</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Common\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:728"/>
      <filename>Mso9.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:467" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:219"/>
      <filename>MSO.DLL</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie6-20040929.115007</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="equals">Software\Microsoft\Windows\CurrentVersion\Internet Settings</key>
      <name operation="equals">DisableCachingOfSSLPages</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:47" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Msxml5.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:3" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Msxml3.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Msxml6.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX82</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:500" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643-DirectX9</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB839643</key>
      <name>Installed</name>
    </registry_object>
    <isainfo_object id="oval:org.mitre.oval:obj:2704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris"/>
    <uname_object id="oval:org.mitre.oval:obj:2733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix"/>
    <patch_object id="oval:org.mitre.oval:obj:2090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118844</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1347" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\Tcpip\Parameters</key>
      <name>EnablePMTUDiscovery</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB893086\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWsndmr</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:399" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">113575</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>quartz.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q19696</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1531" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>itircl.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB825119</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:504" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841872</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>psxss.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:503" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems</key>
      <name>Posix</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUWNsmbar</pkginst>
    </package_object>
    <inetd_object id="oval:org.mitre.oval:obj:505" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="pattern match">^.*smbd.*</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msgsvc.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wkssvc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828035</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\Messenger</key>
      <name operation="equals">Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>ciodm.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Server 2003\SP1\KB871250\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:279" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>gdi32.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:2081" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_32606</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:124" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2DFE1608-BDCA-11D1-B7AE-00C04FB92F3D}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:2" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:619"/>
      <filename>Gifimp32.flt</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:1497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWinamd</pkginst>
    </package_object>
    <registry_object id="oval:org.mitre.oval:obj:509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB834707-ie501sp3-20040929.121357</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1603" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB867801</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc</path>
      <filename>pam.conf</filename>
      <line operation="pattern match">[^#]*pam_krb5.*debug</line>
    </textfilecontent_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc</path>
      <filename>syslog.conf</filename>
      <line operation="pattern match">^[^#]*(\*|daemon)\.debug</line>
    </textfilecontent_object>
    <patch_object id="oval:org.mitre.oval:obj:515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112300</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112085</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>cdo.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:517" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Exchange Server 5.5\SP5\842436a</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\MSExchangeweb</key>
      <name operation="pattern match">.*</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:313" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">106938</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:312" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109326</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:311" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112970</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="pattern match" datatype="string">SUNWcsx?u</pkginst>
    </package_object>
    <process_object id="oval:org.mitre.oval:obj:1496" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="equals" datatype="string">/usr/sbin/in.named</command>
    </process_object>
    <registry_object id="oval:org.mitre.oval:obj:1607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824141</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1605" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\UtilMan</key>
      <name operation="equals">Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:521" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/etc/krb5</path>
      <filename>krb5.conf</filename>
    </file_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc/krb5</path>
      <filename>krb5.conf</filename>
      <line operation="pattern match">^[^#]auth_to_local.*</line>
    </textfilecontent_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1791" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>balsa</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>balsa</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Control\Terminal Server</key>
      <name operation="equals">ProductVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q324380</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\RDPWD</key>
      <name operation="equals">Start</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWapchu</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWftpu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:529" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114564</base>
    </patch_object>
    <inetd_object id="oval:org.mitre.oval:obj:528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/sbin/in.ftpd</service_name>
    </inetd_object>
    <registry_object id="oval:org.mitre.oval:obj:1710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\SP2SRP1</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1616" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>idq.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1615" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q300972</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <metabase_object id="oval:org.mitre.oval:obj:1614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="equals">LM\W3SVC</key>
      <id datatype="int" operation="equals">6014</id>
    </metabase_object>
    <file_object id="oval:org.mitre.oval:obj:522" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Ipnathlp.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\kb823353</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:532" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_USERS</hive>
      <key operation="pattern match">^S-[-0-9]+\\Identities\\\{[-0-9A-Z]+\}\\Software\\Microsoft\\Outlook\ Express\\5\.0\\Mail$</key>
      <name operation="equals">ShowHybridView</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1617" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q823980</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1619" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kdebase</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1618" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>kdm</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q277873</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107702</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109354</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:536" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114497</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1622" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>xenroll.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1621" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q323172</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:540" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:224"/>
      <filename>Swflash.ocx</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1625" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>xactsrv.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1624" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q326830</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1623" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\lanmanserver</key>
      <name operation="equals">Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Ntoskrnl.exe</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWdtdmn</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108221</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:302" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>vdmdbg.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:464" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>nddenb32.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:393" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>netdde.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841533</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>cryptui.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1629" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB823182</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1628" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1001</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1627" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1001</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:547" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWnisu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108750</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110322</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:545" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*ypbind.*</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:275" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">108993</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">115677</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121321</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">108994</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">115678</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121322</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:307" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>grpconv.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:292" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:207"/>
      <filename>shell32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\PowerPoint\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1631" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>ism.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1630" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q321599</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:222"/>
      <filename>cdoex.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Ipnathlp.dll</filename>
    </file_object>
    <metabase_object id="oval:org.mitre.oval:obj:556" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key>LM\W3SVC</key>
      <id datatype="int">6032</id>
    </metabase_object>
    <file_object id="oval:org.mitre.oval:obj:559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wwmp.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:2219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:112"/>
      <filename>rdpwd.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (1.5.0.2)</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>lbxproxy</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1632" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107654</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB841873</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:301" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107893</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:568" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_34544</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>WUFTP-26.INETSVCS-FTP</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:1973" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33395</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_34545</patch_name>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>win32k.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1349" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840987</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:572" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{89820200-ECBD-11cf-8B85-00AA005B4395}</key>
      <name>IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Windows NT\CurrentVersion\Hotfix\KB841356</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Shared Tools</key>
      <name>SharedFilesDir</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:573" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:227"/>
      <filename>fpadmdll.dll</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:2380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ARRAY-MGMT</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2623" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.ADMN-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:2700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_23263</patch_name>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:575" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWpcu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:300" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107115</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:315" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109320</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:314" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">113329</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:578" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\VisualStudio\7.1</key>
      <name xsi:nil="true"/>
    </registry_object>
    <environmentvariable_object id="oval:org.mitre.oval:obj:577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <name>windir</name>
    </environmentvariable_object>
    <file_object id="oval:org.mitre.oval:obj:576" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:228"/>
      <filename>Gdiplus.dll</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:580" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWstm</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:579" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">117367</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:280" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:206"/>
      <filename>wdhtmled.ocx</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:2288" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112669</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1949" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112668</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116341</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2010" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116340</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120720</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2345" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120719</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118966</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:582" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Updates\Windows XP\SP2\KB914798</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:583" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB890923 \Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.UX2-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_32149</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_32926</patch_name>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>httpd</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1633" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sendmail</name>
    </rpminfo_object>
    <patch_object id="oval:org.mitre.oval:obj:290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108528</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:289" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112233</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:589" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Updates\Windows Server 2003\SP1\KB914798</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wjgdw400.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_33214</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:594" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_33215</patch_name>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWgzip</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112668</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-perl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1638" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1636" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl096b</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/tmp</path>
      <filename xsi:nil="true"/>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS2-RUN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_29462</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{903B0409-6000-11D3-8CFE-0050048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1339" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">Software\\Microsoft\\Office\\10\.0\\Registration\\.*</key>
      <name>ProductID</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:66" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:619"/>
      <filename>Png32.flt</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:605" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109764</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116047</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:603" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119596</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109765</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121995</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118813</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">117350</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118558</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">117351</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118559</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:621" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/usr/share/gnome/gnome-about</path>
      <filename>gnome-version.xml</filename>
      <line operation="pattern match">\s*&lt;description>2\.0\.0.*&lt;/description>\s*</line>
    </textfilecontent_object>
    <patch_object id="oval:org.mitre.oval:obj:620" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114644</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:619" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114645</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:618" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114686</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:617" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/usr/share/gnome/gnome-about</path>
      <filename>gnome-version.xml</filename>
      <line operation="pattern match">\s*&lt;description>2\.0\.2.*&lt;/description>\s*</line>
    </textfilecontent_object>
    <patch_object id="oval:org.mitre.oval:obj:616" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">115738</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:615" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114687</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">115739</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/usr/share/gnome-about</path>
      <filename>gnome-version.xml</filename>
      <line operation="pattern match">\s*&lt;distributor-version>Sun Java Desktop System, Release 2&lt;/distributor-version>\s*</line>
    </textfilecontent_object>
    <patch_object id="oval:org.mitre.oval:obj:612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121092</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:609" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118822</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118844</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:623" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33159</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:624" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB885250</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:283" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>hypertrm.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:627" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB873339\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:626" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key>htfile</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:625" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key>telnet\shell\open</key>
      <name>command</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:2535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>SystemRoot</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:2048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:26"/>
      <filename>umpnpmgr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:2558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>CSDVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:630" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\MediaPlayer\10.0\Registration</key>
      <name>UDBVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:592" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Wmp.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Imekr61.ime</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:631" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>jgdw400.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>netlogon.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>rasmans.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:632" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_32280</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:635" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>SysMgmtServer.MX-PORTAL</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>SysMgmtServer.MX-PORTAL</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:638" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120329</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120330</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:636" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path>/etc</path>
      <filename>pam.conf</filename>
      <line operation="pattern match">^other.*krb5.*</line>
    </textfilecontent_object>
    <registry_object id="oval:org.mitre.oval:obj:1700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q320206</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1641" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>smss.exe</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_29249</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:641" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33792</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:1404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS2-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:645" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.CORE-ENG-A-MAN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:644" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.UX-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:643" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_33967</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:465" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\KB885492</key>
      <name operation="equals">PackageVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:646" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{ 3e7bb08a-a7a3-4692-8eac-ac5e7895755b}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:647" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:229"/>
      <filename>Npdsplay.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:648" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:224"/>
      <filename>Flash.ocx</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:649" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\PowerPoint\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:524" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\PowerPnt.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:223"/>
      <filename>owerPnt.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:650" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Office\9.0\Registration</key>
      <name>ProductID</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:984" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>Networking.NET2-KRN</swlist>
    </swlist_object>
    <file_object id="oval:org.mitre.oval:obj:1549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>kernel32.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:276" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wins.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB870763</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1372" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\wins</key>
      <name>Start</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:653" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>Secure_Shell.SECURE_SHELL</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:656" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">111571</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:654" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">115880</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:322" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110943</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:660" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90840409-6000-11D3-8CFE-0150048383C9}</key>
      <name>InstallLocation</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:659" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:230"/>
      <filename>xlview.exe</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108117</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:664" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Excel\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1644" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>httpd</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1643" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="pattern match">.*</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <patch_object id="oval:org.mitre.oval:obj:1620" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">110286</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/dt/bin</path>
      <filename>rpc.ttdbserverd</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:666" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>HP_Webproxy.HPWEB-PX-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:665" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34163</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1388" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox \((0\..*|1\.0\..*\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1386" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla \(.*\)</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1648" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/openwin/lib</path>
      <filename>fs.auto</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1647" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">109862</base>
    </patch_object>
    <inetd_object id="oval:org.mitre.oval:obj:1646" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/openwin/lib/fs.auto</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1645" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>xfs</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:670" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Outlook\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:669" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:232"/>
      <filename>msmapi32.dll</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWwbmc</pkginst>
    </package_object>
    <process_object id="oval:org.mitre.oval:obj:671" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">.*smcboot</command>
    </process_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1650" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gtkhtml</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1649" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>evolution</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWnsb</pkginst>
    </package_object>
    <swlist_object id="oval:org.mitre.oval:obj:678" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:677" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:676" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_23948</patch_name>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109023</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:682" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120240</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109024</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">120239</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q313829</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:685" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWsmbau</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">114684</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:684" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*smbd.*</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:686" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34102</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q817606</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:689" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-UTIL</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-ADMIN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:687" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>CIFS-Server.CIFS-LIB</swlist>
    </swlist_object>
    <registry_object id="oval:org.mitre.oval:obj:692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Outlook\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:233"/>
      <filename>msmapi32.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_30402</patch_name>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1653" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>mup.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1652" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q312895</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:673" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">111313</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">111314</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:672" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116807</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116808</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121308</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121309</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q314147</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:973" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>snmp.exe</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_23950</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.CORE-ENG-A-MAN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.UX-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_33989</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1655" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q246009</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>OS-Core.UX-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_33219</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1360" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1659" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>shdocvw.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1658" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{90A2A715-D986-4EAB-8C73-4D06114EF760}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1657" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1656" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1803</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWlzas</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">121332</base>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>IPSec.IPSEC2-KRN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:715" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>IPSec.IPSEC2-KRN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>TOUR_PRODUCT.T-NET2-KRN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:983" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_32606</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Clients\Media\Winamp\shell\open</key>
      <name>command</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:234"/>
      <filename/>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1660" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Transaction Server\Packages</key>
      <name operation="equals">Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>Xsun</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\SNMP</key>
      <name operation="equals">Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1662" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>tcpcfg.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1661" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q265714</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1663" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gtkhtml</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msjava.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1665" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gnupg</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1664" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gnupg</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890175</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>FreeRADIUS</name>
    </rpminfo_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">udp</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="equals">1812</local_port>
    </inetlisteningservers_object>
    <swlist_object id="oval:org.mitre.oval:obj:1365" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>hpuxwsAPACHE</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1364" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>hpuxwsAPACHE</swlist>
    </swlist_object>
    <file_object id="oval:org.mitre.oval:obj:379" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>mstask.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{bfb56e60-5895-496c-bd6b-459b97142e4c}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1666" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Active Setup\Installed Components\{4f645220-306d-11d2-995d-00c04f98bbc9}</key>
      <name>Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\ NT\\CurrentVersion\\Hotfix\\[Kk][Bb]834707[-a-zA-Z0-9.]*$</key>
      <name>Installed</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:726" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_34543</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>WUFTP-26.INETSVCS-FTP</swlist>
    </swlist_object>
    <registry_object id="oval:org.mitre.oval:obj:1626" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Word\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:278" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>httpext.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB824151</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\W3SVC\Parameters</key>
      <name operation="equals">DisableWebDAV</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1668" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ghostscript</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gs</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885835</key>
      <name>Installed</name>
    </registry_object>
    <metabase_object id="oval:org.mitre.oval:obj:1757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="equals">LM\W3SVC</key>
      <id datatype="int" operation="equals">6014</id>
    </metabase_object>
    <file_object id="oval:org.mitre.oval:obj:730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:235"/>
      <filename>Mdbmsg.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>tcpip.sys</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1460" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108376</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:737" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.wvx</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:736" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.wpl</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:735" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.wmx</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:734" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.wms</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:733" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.wmz</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\MediaPlayer\9.0\Registration</key>
      <name>UDBVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:527" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wmp.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Windows Media Player 9\SP0\KB885492</key>
      <name operation="equals">PackageVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:739" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.asx</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:738" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">\SOFTWARE\Classes\.wax</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB891711</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:390" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>user32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q319733</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:496" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:203"/>
      <filename>w3svc.dll</filename>
    </file_object>
    <metabase_object id="oval:org.mitre.oval:obj:1748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="equals">LM\W3SVC</key>
      <id datatype="int" operation="equals">6014</id>
    </metabase_object>
    <file_object id="oval:org.mitre.oval:obj:531" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>hhctrl.ocx</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{839117ee-2132-4bae-a56a-42b50204c9b9}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB889293</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1348" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB893066</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:588" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>tcpip.sys</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>Mozilla.MOZ-COM</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>Mozilla.MOZ-COM</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1359" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:1358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_23949</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1572" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890859</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox 1.0.7</key>
      <name>DisplayName</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_34306</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1654" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811493</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:335" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>Ntoskrnl.exe</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>Secure_Shell.SECURE_SHELL</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>Secure_Shell.SECURE_SHELL</swlist>
    </swlist_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1413" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mozilla</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\MediaPlayer\8.0\Registration</key>
      <name>UDBVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Wmpui.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1367" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896426</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:658" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>netman.dll</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultWS.WS-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34123</patch_name>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gedit</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gedit</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>sudo</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/etc</path>
      <filename>sudoers</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>sudo</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:389" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:215"/>
      <filename>wordpad.exe</filename>
    </file_object>
    <inetd_object id="oval:org.mitre.oval:obj:1744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/lib/fs/cachefs/cachefsd</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/lib/fs/cachefs</path>
      <filename>cachefsd</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108800</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:1341" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34169</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultTS.VV-IWS</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultWS.WS-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34121</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultTS.VV-IWS</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34170</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:774" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultWS.WS-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34120</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:772" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultTS.VV-IWS</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34171</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VaultWS.WS-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34119</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>HP_Webproxy.HPWEB-PX-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34203</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>HP_Webproxy.HPWEB-PX-CORE</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_34204</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1518" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Word\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1517" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:221"/>
      <filename>wordview.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\MediaPlayer\7.1\Registration</key>
      <name>UDBVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>wmpui.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1670" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Classes\MIME\Database\Content Type\application/hta</key>
      <name operation="equals">Extension</name>
    </registry_object>
    <package_object id="oval:org.mitre.oval:obj:784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWmoznav</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:783" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWmozmail</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:782" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">117765</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">117767</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:787" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key operation="equals">MITrain.Document\shell\open\command</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:786" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:237"/>
      <filename>Orun32.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\Step by Step Interactive Training\SP2\KB898458\Filelist</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Msdtctm.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:628" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>webclnt.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_24395</patch_name>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:212"/>
      <filename>msadco.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1669" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Ole</key>
      <name operation="equals">EnableDCOM</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:789" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>cdoex.dll</filename>
    </file_object>
    <inetd_object id="oval:org.mitre.oval:obj:1673" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/openwin/bin/kcms_server</service_name>
    </inetd_object>
    <file_object id="oval:org.mitre.oval:obj:1672" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>kcms_server</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB890923 -ie501sp3-20050225.100153</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:792" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libgd</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:791" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libgd-devel</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB890046</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1000" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:759"/>
      <filename>agentdpv.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1510" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Word\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:221"/>
      <filename>winword.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1387" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (1.5)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Mozilla\Mozilla Firefox 1.5\bin</key>
      <name>PathToExe</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:226"/>
      <filename/>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Firefox (1.5.0.1)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:797" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mozilla Thunderbird (1.5)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:796" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Mozilla\Mozilla Thunderbird 1.5\bin</key>
      <name>PathToExe</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:238"/>
      <filename/>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SeaMonkey \((1\.0[ab]|1\.0)\)</key>
      <name>DisplayName</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:966" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>itss.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840315</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Classes\ITSProtocol</key>
      <name operation="pattern match">.*</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:213"/>
      <filename>SRV.SYS</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB817606</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:2756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33159</patch_name>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:800" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libxml</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>libxml-devel</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1676" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server</key>
      <name operation="equals">VersionMajor</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Fpc\Hotfixes\SP1\277</key>
      <name operation="equals">Kbs</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gzip</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1527" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>gunzip</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1378" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Applets\Wordpad</key>
      <name operation="equals">EnableLegacyConverters</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:801" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:239"/>
      <filename>mswrd632.wpc</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:803" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:240"/>
      <filename>msmapi32.dll</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:1890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118844</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2245" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119450</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:2729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119449</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873333</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1415" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Excel\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:663" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:662" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:231"/>
      <filename>excel.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>bzip2</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:809" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:808" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33791</patch_name>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:391" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>hlink.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Quartz.dll</filename>
    </file_object>
    <swlist_object id="oval:org.mitre.oval:obj:811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>WUFTP-26.INETSVCS-FTP</swlist>
    </swlist_object>
    <file_object id="oval:org.mitre.oval:obj:708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msieftp.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft ISA Server SP</key>
      <name operation="equals">DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall</key>
      <name>Microsoft ISA Server</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:251"/>
      <filename>w3proxy.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\FPC\Hotfixes\SP1\430</key>
      <name operation="equals">kbs</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1575" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896422</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:242"/>
      <filename>srv.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896727</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:815" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>telnet</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:814" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>telnet</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:326" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>mrxsmb.sys</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{2298d453-bcae-4519-bf33-1cbf3faf1524}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB896428</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:816" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>telnet.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:661" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>cdosys.dll</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:818" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWbnuu</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:817" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">106952</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:657" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">111570</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:655" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">113322</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:668" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Fontsub.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>T2embed.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1545" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB901214</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>mscms.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>fetchmail</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1677" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gdm</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB824146</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:254" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>rpcrt4.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:822" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:821" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-hugemem</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:820" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-smp</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1577" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\CLASSES\PNGFilter.CoPNGFilter</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:281" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
      <name>CommonFilesDir</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:377" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:206"/>
      <filename>dhtmled.ocx</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:823" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB891781</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:2678" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_33427</patch_name>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:828" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWkr5sv</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWkr5sl</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:826" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWkrgdo</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:825" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWkrggl</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112536</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112908</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:447" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112237</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112390</base>
    </patch_object>
    <textfilecontent_object id="oval:org.mitre.oval:obj:824" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <path operation="equals">/etc/krb5</path>
      <filename>krb5.conf</filename>
      <line operation="pattern match">^[^#_]*default_realm[^=]*=[^_]*$</line>
    </textfilecontent_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1529" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>gzip</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:829" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>zgrep</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:652" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>nwwks.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:336" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>sxs.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/lib/snmp</path>
      <filename>snmpdx</filename>
    </file_object>
    <process_object id="oval:org.mitre.oval:obj:1782" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*inetd.*</command>
    </process_object>
    <inetd_object id="oval:org.mitre.oval:obj:1763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <protocol operation="pattern match">.*</protocol>
      <service_name operation="equals">/usr/dt/bin/rpc.ttdbserverd</service_name>
    </inetd_object>
    <package_object id="oval:org.mitre.oval:obj:831" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="pattern match" datatype="string">SUNWtltkx?</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:830" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">112808</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:994" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\Microsoft\Active Setup\Installed Components\{754D29C1-0C97-405F-98D0-21B212CA7FF1}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:832" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB819696</key>
      <name>Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1002" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>schannel.dll</filename>
    </file_object>
    <metabase_object id="oval:org.mitre.oval:obj:1014" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <key datatype="string" operation="pattern match">^LM\\W3SVC\\.*$</key>
      <id datatype="int" operation="equals">5506</id>
    </metabase_object>
    <registry_object id="oval:org.mitre.oval:obj:1011" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\PCT 1.0\Server</key>
      <name operation="equals">Enabled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:834" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
      <name>ieHardenadmin</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:833" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OC Manager\Subcomponents</key>
      <name>ieHardenuser</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1679" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>ntdll.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1678" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q815021</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-9]\)|\(1\.7\.10\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-6]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1635" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB897715</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <process_object id="oval:org.mitre.oval:obj:1383" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">\bpostmaster\b</command>
    </process_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:836" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>rh-postgresql-contrib</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:835" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/lib/pgsql</path>
      <filename>tsearch.so</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:837" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Mapi32.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1363" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>bzip2</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:838" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>bzgrep</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:629" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion</key>
      <name operation="equals">Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\LmHosts</key>
      <name operation="equals">Start</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:839" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SYSTEM\\CurrentControlSet\\Services\\NetBT\\Parameters\\Interfaces\\Tcpip.*$</key>
      <name operation="equals">NetbiosOptions</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:841" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>ssnetlib.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:846" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB893756</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\TapiSrv</key>
      <name operation="equals">Start</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:848" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119985</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:847" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">122082</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>mozilla</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:1030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>mozilla</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>rpcss.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Exchange\Setup</key>
      <name>ServicePackBuild</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:236"/>
      <filename>mdbmsg.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>evolution</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:850" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\PowerPoint\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:554" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\powerpnt.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:553" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:225"/>
      <filename>powerpnt.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>Msw3prt.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>jscript.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:857" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openoffice</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:856" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>oocalc</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:855" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>oodraw</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:854" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ooffice</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:853" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>ooimpress</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:852" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>oowriter</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:858" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>mf3216.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:622" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Gdi32.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:807" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Mf3216.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:849" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>comsvcs.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:728" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>cryptdlg.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:802" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB885836</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:859" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:244"/>
      <filename>hh.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>crypt32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:860" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329115</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1009" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Services\Netlogon</key>
      <name>Start</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msgina.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:339" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>zipfldr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:864" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB873376</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:863" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Classes\CompressedFolder</key>
      <name operation="equals">FriendlyTypeName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:865" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Rockliffe\MailSite</key>
      <name operation="equals">Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1728" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q293826</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1007" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1006" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-devel</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl-perl</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1004" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl096</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>openssl096b</name>
    </rpminfo_object>
    <process_object id="oval:org.mitre.oval:obj:1777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*snmpdx.*</command>
    </process_object>
    <package_object id="oval:org.mitre.oval:obj:869" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst operation="equals" datatype="string">SUNWsasnm</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:868" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">107709</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">108869</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:870" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>umandlg.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB896423</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:924" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/X11/bin</path>
      <filename>Xorg</filename>
    </file_object>
    <patch_object id="oval:org.mitre.oval:obj:875" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119059</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">108653</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:873" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119060</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:872" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match">.*Xsun\b.*</command>
    </process_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:877" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cvs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:406" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>ole32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:962" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\DataAccess\Q823718</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>odbcbcp.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:359" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\DataAccess</key>
      <name>FullInstallVer</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>fetchmail</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>fetchmail</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\SeaMonkey \(1\.0[ab]\)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\mozilla.org\SeaMonkey</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-7]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\)|\(1\.0\.[0-7]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-9]\)|\(1\.7\.1[0-2]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <patch_object id="oval:org.mitre.oval:obj:1883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHCO_28847</patch_name>
    </patch_object>
    <swlist_object id="oval:org.mitre.oval:obj:2529" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>DCE-Core.DCE-CORE-SHLIB</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:2602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>SW-DIST.SD-AGENT</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:2770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHSS_29963</patch_name>
    </patch_object>
    <uname_object id="oval:org.mitre.oval:obj:2759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix"/>
    <registry_object id="oval:org.mitre.oval:obj:1010" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB828741</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:955" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Ole</key>
      <name>EnableDCOMHTTP</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:887" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>rpcproxy.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Locator.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1682" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q810833</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\RPCLocator</key>
      <name operation="equals">Start</name>
    </registry_object>
    <swlist_object id="oval:org.mitre.oval:obj:891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INETSVCS-RUN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>InternetSrvcs.INET-ENG-A-MAN</swlist>
    </swlist_object>
    <swlist_object id="oval:org.mitre.oval:obj:889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swlist>VirtualVaultOS.VVOS-AUX-IA</swlist>
    </swlist_object>
    <patch_object id="oval:org.mitre.oval:obj:888" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <patch_name>PHNE_24395</patch_name>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:892" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB837009</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:897" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX8</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:895" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX81</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:894" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX82</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\DirectX</key>
      <name>Version</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>dplayx.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:893" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB839643-DirectX9</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1578" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\HotFix\KB883939</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\MSSQLServer\MSSQLServer\CurrentVersion</key>
      <name operation="equals">CurrentVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>sqlservr.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:903" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>odsole70.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:902" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>xpqueue.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:901" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>xprepl.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:900" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>xplog70.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>xpweb70.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:842" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\sqlservr.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:243"/>
      <filename>xpstar.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:906" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
      <name operation="equals">Bind</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:905" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
      <name operation="equals">Export</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:904" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Services\NetBIOS\Linkage</key>
      <name operation="equals">Route</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:907" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:911" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\.*</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:329" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Exchange\Setup</key>
      <name>Services</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:910" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:210"/>
      <filename>mad.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:909" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\Microsoft\Updates\Exchange Server 2000\SP3\Q316056</key>
      <name operation="pattern match">.*</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg</key>
      <name operation="equals">Everyone</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
      <name>ProductSuite</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q299444</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:913" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>winlogon.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:912" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q317636</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/usr/lib/netsvc</path>
      <filename>rpc.yppasswdd</filename>
    </file_object>
    <process_object id="oval:org.mitre.oval:obj:1719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match" datatype="string">^.*rpc\.yppasswdd.*</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:1684" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int" operation="equals">111590</base>
    </patch_object>
    <registry_object id="oval:org.mitre.oval:obj:1739" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q295534</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q301625</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:915" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel-unsupported</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Control\ProductOptions</key>
      <name>ProductType</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>lsasrv.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:253" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>shell32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[1-3]$</key>
      <name>1802</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1774" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{D7B44F3E-77D3-44C5-8E03-4222D9A18B7B}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{61E6EAE5-7821-4AC1-9BBD-AED032A8E273}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1772" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{FF4DD9CD-F25E-425a-8B5C-A2D062781FBB}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{2757B1D6-0367-4663-877C-93ECC5C01BF6}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{C34F4917-ED43-439f-9023-97B0024A2B3B}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{F9C174E3-3E87-40bc-AA94-B8974F2B9222}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{f5de1b93-9d38-416b-b09e-aa85a8e84309}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{377483c2-e4b4-4ee8-b577-9aed264c8735}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{96543d59-497a-4801-a1f3-5936aacaf7b1}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{057997dd-71e4-43cc-b161-3f8180691a9e}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{eddbec60-89cb-44ef-8291-0850fd28ff6a}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:993" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\Microsoft\Active Setup\Installed Components\{716E024F-7F74-47F3-B93B-9FF7F3CBF94C}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\Microsoft\Active Setup\Installed Components\{E81659DF-28E1-4C60-B4B9-00A4BC5FA76D}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">Software\Microsoft\Active Setup\Installed Components\{2D5974C5-5185-4f5b-80B6-28015ACDD74C}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:989" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name operation="equals">1803</name>
    </registry_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:930" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>kernel</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>msw3prt.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1016" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Active Setup\Installed Components\{2cc9d512-6db6-4f1c-8979-9a41fae88de0}</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Outlook Express\Version Info</key>
      <name>Current</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>inetcomm.dll</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>ethereal-gnome</name>
    </rpminfo_object>
    <registry_object id="oval:org.mitre.oval:obj:1759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q327696</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q811114</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\INetStp</key>
      <name operation="equals">MajorVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:938" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\INetStp</key>
      <name operation="equals">MinorVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:211"/>
      <filename>w3svc.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:886" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>helpctr.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:917" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB840374</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>msasn1.dll</filename>
    </file_object>
    <inetlisteningservers_object id="oval:org.mitre.oval:obj:1101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <protocol operation="equals">TCP</protocol>
      <local_address operation="pattern match">.*</local_address>
      <local_port operation="pattern match">.*</local_port>
    </inetlisteningservers_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:920" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>squirrelmail</name>
    </rpminfo_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>php</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path operation="equals">/etc/httpd/modules</path>
      <filename>libphp4.so</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:990" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</key>
      <name>Security_HKLM_only</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1671" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name>1200</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:988" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name>1200</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1609" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CURRENT_USER</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name>1400</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\[0-4]$</key>
      <name>1400</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:921" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>evtgprov.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>Msxml4.dll</filename>
    </file_object>
    <package_object id="oval:org.mitre.oval:obj:539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWdtwm</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118953</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">118954</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109931</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:206" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">109932</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114219</base>
    </patch_object>
    <package_object id="oval:org.mitre.oval:obj:204" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWTiff</pkginst>
    </package_object>
    <package_object id="oval:org.mitre.oval:obj:203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <pkginst>SUNWTiffx</pkginst>
    </package_object>
    <patch_object id="oval:org.mitre.oval:obj:202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114220</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119900</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">119901</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:213" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">111844</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:212" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">111845</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:211" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112785</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">112786</base>
    </patch_object>
    <process_object id="oval:org.mitre.oval:obj:526" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <command operation="pattern match">.*httpd</command>
    </process_object>
    <patch_object id="oval:org.mitre.oval:obj:217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116973</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">116974</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:215" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">113146</base>
    </patch_object>
    <patch_object id="oval:org.mitre.oval:obj:214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">114145</base>
    </patch_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:1414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>redhat-release</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:953" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/bin</path>
      <filename>cvs</filename>
    </file_object>
    <rpminfo_object id="oval:org.mitre.oval:obj:933" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <name>cvs</name>
    </rpminfo_object>
    <file_object id="oval:org.mitre.oval:obj:218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>kerberos.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:201"/>
      <filename>rdpwd.sys</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>tapisrv.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>mshtml.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:223" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>spoolsv.exe</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>umpnpmgr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox \(0\.9.*\)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \(0\.[6-8]\)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:229" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-4]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:231" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \(0\.[0-8]\)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird \(0\.[6-9]\)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:232" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\(1\.7\)|\(1\.[0-7]\.[0-3]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:234" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox \(0\.[0-9].*\)</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:235" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:236" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-5]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:238" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-1]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-6]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:241" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-3]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:240" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-7]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Mozilla\Mozilla Thunderbird</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\)|\(1\.0\.[0-2]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-2]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:245" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-4]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:244" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-8]\))</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Mozilla\Mozilla Firefox</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\mozilla.org\Mozilla</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:419" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1015" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\KB835732</key>
      <name>Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1001" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_CLASSES_ROOT</hive>
      <key>HCP</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>SystemRoot</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200"/>
      <filename>helpctr.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:247" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Internet Explorer</key>
      <name>Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:309" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
      <name>ProgramFilesDir</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:308" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:209"/>
      <filename>vgx.dll</filename>
    </file_object>
    <uname_object id="oval:org.mitre.oval:obj:679" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix"/>
    <patch_object id="oval:org.mitre.oval:obj:876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <base datatype="int">108652</base>
    </patch_object>
    <file_object id="oval:org.mitre.oval:obj:1779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <path>/usr/openwin/bin</path>
      <filename>xlock</filename>
    </file_object>
    <family_object id="oval:org.mitre.oval:obj:99" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <registry_object id="oval:org.mitre.oval:obj:123" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>CurrentVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>CSDVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1576" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SYSTEM\CurrentControlSet\Control\Session Manager\Environment</key>
      <name>PROCESSOR_ARCHITECTURE</name>
    </registry_object>
  </objects>
  <states>
    <registry_state id="oval:org.mitre.oval:ste:1454" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>4.1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1453" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.1.0.3934</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1452" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.1.0.3934</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1451" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal">4</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal">4</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">Installed</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2280" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.1.9904</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:50" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7108</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:54" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2976</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2365" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.9716</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2366" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.9315</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.3019</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.599</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:83" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.9.1133</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:91" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.3702</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:80" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">7.10.0.3079</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:78" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">9.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:79" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.3810</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.3708</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">10.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.3265</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:76" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">7.10.0.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">6[,\.]4.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2434" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.6980.57</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2433" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:98" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.0.50727.101</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.588</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:58" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2783</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.3015</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:55" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7110</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>0</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:393" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">13</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3846.2300</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:93" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.50727.236</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.788.1</version>
    </file_state>
    <metabase_state id="oval:org.mitre.oval:ste:537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <data operation="pattern match">^http:*,PERMANENT,*</data>
    </metabase_state>
    <registry_state id="oval:org.mitre.oval:ste:536" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="less than or equal" datatype="int">16384</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7071</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:95" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.0.0.3424</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:70" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.1242</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:841" version="2" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">21</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:840" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:839" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">31</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:913" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/sbin/sadmind</server_program>
    </inetd_state>
    <patch_state id="oval:org.mitre.oval:ste:912" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:911" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:910" version="2" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:909" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/sbin/sadmind</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:74" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.605</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:69" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2817</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:63" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1586</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:67" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.3020</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:57" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.594</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2795</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:97" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2995</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:177" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1578</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:49" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3842.3000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:90" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.607</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:89" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2826</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:134" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.3028</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:88" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1896</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:87" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4971.600</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:61" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">9.0.16.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:59" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">8.0.22.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:86" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.615</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:84" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2837</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.3038</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:82" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7112</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.20.9841.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:48" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3890.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">8.5</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1263" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.142</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:368" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:367" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:456" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:455" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:454" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:491" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">33</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:490" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">18</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:489" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">12</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:994" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.1.9800.9</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:993" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:1199" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1198" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:1203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oread operation="equals" datatype="boolean">true</oread>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1206" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.10.2001.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6904</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:1212" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.23</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:1211" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>KL</area_patched>
      <patch_base operation="greater than or equal">33713</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>KL</area_patched>
      <patch_base operation="greater than or equal">33714</patch_base>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1213" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.7-24</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2739.300</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1506</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.3-0.30E.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.3-0.30E.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1223" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">7:2.5.STABLE3-6.3E</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*squid</program_name>
    </inetlisteningservers_state>
    <file_state id="oval:org.mitre.oval:ste:2760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2719.2200</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">gopher://</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.5.5-1.3EL.0</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <sgid operation="equals" datatype="boolean">true</sgid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1232" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.14i-10.2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1231" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1229" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1236" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">14:3.7.2-7.E3.2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1235" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1234" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1240" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:1.2.2-21</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:1.2.2-21</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1238" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.13-12</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.13-12</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1244" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.11.2-22</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1247" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7255</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33559</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1250" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.8618.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.8618.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1251" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.5.7-4.3E</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1252" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.1.0.3861</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1254" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.134</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1253" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1348</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1256" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.6.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1255" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.746.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1258" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.70.11.40</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.5.6-15</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2715.400</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6898</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1262" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.135</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1261" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1361</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1266" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6906</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1285" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">6:3.1.3-6.4</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1284" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1283" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1282" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1281" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1280" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1279" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1278" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1277" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1276" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1275" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1273" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1272" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1271" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1270" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1268" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1286" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.133</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1287" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.132</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1289" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.2.5-0.4</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1288" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*racoon</program_name>
    </inetlisteningservers_state>
    <patch_state id="oval:org.mitre.oval:ste:3193" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">50</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3924" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:3519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid datatype="boolean">true</suid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid datatype="boolean">true</suid>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3142" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3016" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">39</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3420" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">93</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3126" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">82</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:3943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">7:2.5.STABLE3-5.3E</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1292" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1291" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.0.3.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.0.3.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1293" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.0.3.EL</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.1.0.3932</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1299" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.1.0.3931</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1298" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1302" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6672</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1301" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1304" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.279</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1303" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1306" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.780.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1307" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4927.2100</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1309" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2713.1100</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1308" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1310" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.139</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1311" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2716.2200</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1321" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4613.1700</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1320" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1325" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.134</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1326" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">37:1.4.2-3.0.2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1328" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.164</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1329" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.3649</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1330" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.1880.14</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1331" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2506</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1332" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.769.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1333" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6901</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1335" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.125</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1336" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.87.1964.1880</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1345" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.135</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1361</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">0.9.3940.20</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1347" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.134</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1346" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1361</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1349" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7263</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1348" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33562</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6895</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1353" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7255</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1352" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33559</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1355" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6904</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2195.6899</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.2195.6824</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2772" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5080</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1360" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.3-0.30E.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1359" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.3-0.30E.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.136</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1361" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1347</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1367" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4939.300</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:1374" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1373" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1372" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1371" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1370" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1369" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">01</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.3-0.90.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.3-0.90.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1383" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1382" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1381" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1379" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1378" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1377" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1375" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1387" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">7:2.5STABLE1-3.9</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1386" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*squid.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1388" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.46-32.ent</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1392" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">37:1.4.2-0.9.0</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1391" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1390" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1389" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1393" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">37:1.4.2-0.9.0</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1397" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-33.4</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-33.4</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1395" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-33.4</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1394" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6b-16</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1399" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.0.9-2.30E.1</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1398" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*snmpd.*</program_name>
    </inetlisteningservers_state>
    <uname_state id="oval:org.mitre.oval:ste:1401" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <machine_class operation="equals">x86_64</machine_class>
    </uname_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1400" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-4.0.2.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1403" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-4.0.2.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1402" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-4.0.2.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.11.2-14</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1406" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">6:3.1.3-3.3</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.46-26.ent</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.40-21.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.0.7-4.EL3.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1411" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.6-7.EL</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*rpc\.mountd</program_name>
    </inetlisteningservers_state>
    <patch_state id="oval:org.mitre.oval:ste:2778" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">51</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-28.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1413" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-28.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-28.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">6:3.1-6</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uread operation="equals" datatype="boolean">true</uread>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1415" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1429" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.0a-0.90.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1428" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.10.0a-0.90.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1427" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1421" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1419" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1431" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.11.2-13</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1430" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <owrite operation="equals" datatype="boolean">true</owrite>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1432" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">14:3.7.2-7.E3.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1433" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.0.7-4.rhl9.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">14:3.7.2-7.9.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1435" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1434" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1440" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.22.0-6.1.0</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1439" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.22.0-6.1.0</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1438" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.22.0-6.1.0</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.22.0-6.0.3</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.22.0-6.0.3</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1441" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.22.0-6.0.3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">6.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.0.211</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.5709.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1447" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">10.0.4333.0</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">5:1.4.1-3.4</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-30.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-30.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1456" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-30.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1461" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.5.10-6</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1460" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.5.10-6</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1459" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.5.10-6</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1462" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.3.0-55.EL</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.428.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1464" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.0.1-4</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1463" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*httpd</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1465" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.0.2-6.3E</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1466" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.7-7.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.0.1.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.0.1.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1467" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-9.0.1.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">6:3.1-13</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:4.6.0-7.9</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.7-2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1476" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <sgid operation="equals" datatype="boolean">true</sgid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1475" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2782" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.213.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.213.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.75-0.9.0</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1483" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">3:2.1.1-5</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">5:1.4.1-3.3</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1489" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:9.24-11.30.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:9.24-11.30.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:9.24-11.30.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.3.0-2.90.55</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2171" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:9.24-10.90.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:9.24-10.90.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:9.24-10.90.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2160" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2157" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2149" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2146" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2145" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2142" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2140" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2137" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2135" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2134" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2133" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2132" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2131" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2128" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2127" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2125" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2124" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2123" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2121" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2120" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2119" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2116" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2114" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2113" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2098" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2096" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2094" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2093" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2092" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2091" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2089" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2088" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2087" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2085" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2084" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2083" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2082" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2081" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2080" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2079" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2078" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2076" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2073" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2072" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2071" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2070" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2069" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2068" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2065" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2064" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2063" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2062" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2061" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2060" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2059" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2058" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2057" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2056" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2055" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2054" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2053" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2052" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2051" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2050" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2047" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2045" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2043" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2041" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2040" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2038" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2037" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2036" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2035" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2034" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2033" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2032" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2028" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2027" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2026" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2025" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2024" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2023" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2022" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2021" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2020" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2019" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2018" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2017" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2016" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2015" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2014" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2013" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2012" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2011" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2010" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2009" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2007" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2006" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2004" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2002" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2001" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2000" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1998" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1997" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1996" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1995" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1994" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1993" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1990" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1989" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1988" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1987" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1986" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1985" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1984" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1983" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1982" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1980" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1979" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1977" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1975" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1974" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1973" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1972" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1971" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1970" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1969" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1968" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1966" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1963" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1962" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1961" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1960" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1959" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1958" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1957" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1956" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1955" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1954" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1953" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1952" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1951" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1950" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1949" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1948" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1947" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1946" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1944" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1942" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1941" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1940" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1938" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1937" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1936" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1935" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1934" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1933" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1932" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1931" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1930" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1928" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1927" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1926" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1925" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1924" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1921" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1920" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1917" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1915" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1913" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1912" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1911" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1910" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1909" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1907" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1906" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1905" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1904" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1903" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1902" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1901" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1900" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1897" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1895" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1894" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1893" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1892" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1888" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1887" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1886" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1885" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1884" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1877" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1875" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1873" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1872" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1870" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1869" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1868" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1865" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1864" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1863" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1860" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1859" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1858" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1857" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1856" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1855" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1854" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1853" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1852" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1850" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1849" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1848" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1847" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1846" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1842" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1841" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1839" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1838" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1837" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1836" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1835" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1834" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1833" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1832" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1831" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1830" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1829" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1828" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1826" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1825" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1824" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1823" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1822" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1821" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1820" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1818" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1817" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1816" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1815" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1814" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1809" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1808" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1807" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1806" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1805" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1803" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1802" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1801" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1800" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1797" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1796" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1792" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1791" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1789" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1788" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1787" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1786" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1783" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1782" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1774" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1772" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1739" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1736" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1734" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1728" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1726" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1715" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1689" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1687" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1686" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1685" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1684" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1682" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1679" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1678" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1677" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1676" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1673" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1672" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1671" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1670" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1669" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1668" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1666" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1665" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1664" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1663" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1662" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1661" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1660" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1659" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1658" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1657" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1656" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1655" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1654" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1653" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1652" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1650" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1649" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1648" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1647" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1646" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1645" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1644" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1643" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1641" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1638" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1636" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1635" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1633" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1632" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1631" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1630" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1629" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1628" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1627" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1626" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1625" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1624" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1623" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1622" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1621" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1620" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1619" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1618" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1617" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1616" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1615" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1609" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1605" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1603" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1594" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1592" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1589" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1588" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1583" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1582" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1580" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1579" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1578" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1576" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1575" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1573" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1572" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1568" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1556" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1554" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1553" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1547" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1545" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1540" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1536" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1532" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1531" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1529" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1527" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1526" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1524" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1522" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1521" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1517" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1505" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1504" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1500" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1496" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1494" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2173" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.7-4.1</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">.*</program_name>
    </inetlisteningservers_state>
    <file_state id="oval:org.mitre.oval:ste:2174" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.99</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2175" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33554</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7255</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2783" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">19</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2177" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.88</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2178" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6775.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.119</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1274</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2182" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6824</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2784" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">1</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2516</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2195" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base>29269</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base>30275</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base>32181</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2201" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.3000.2073.13</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2200" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">2.2</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2199" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">3.0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2198" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">7.0.1701.44</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2197" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">3.5</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.1969.33</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.360</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.3407</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2205" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.160</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6987</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2212" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.85.1025.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2211" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.85.1025.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2210" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2476</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:2223" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.10.01</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.10.01</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.10.10</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.10.10</version>
    </swlist_state>
    <uname_state id="oval:org.mitre.oval:ste:2219" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.01</os_release>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:2218" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.10</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:2217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">23947</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33790</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2787" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5695</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3553" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.81.9002.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2232" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.81.9002.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.81.9042.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2229" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.81.9042.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">6.00.2900.2180</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:266" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2523</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:265" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2524</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:264" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2788" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">4</version>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">D\.5\.8\.0\.[ABCDEF]</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>D.5.8.3.A</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">D\.5\.8\.2\.[ABCDE]</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3647" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">D\.5\.6\..*</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">D\.5\.8\.2\.[ABC]</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:2237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">7.0.8002.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3131" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3692" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3372" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">15</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3437" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3614" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3009" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3847" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2964" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:46" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1863</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:119" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2745</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:81" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2938</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.558</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:10" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7100</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2240" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.316</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:2.0.14-4</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2241" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2245" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7071</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2244" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7073</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.5.6-14</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.296.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2252" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2521</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2255" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6870</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2254" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2261" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2260" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">12</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2259" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">16</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2258" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">19</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2796" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">7</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:2795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/dt/bin/dtspcd</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2792" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2264" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2777</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2263" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2777</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.5815.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:16" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.99.72</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2270" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1790</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2277" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7177</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2276" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7177</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2275" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7202</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7207</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2273" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2799" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">2</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.193</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:268" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.193</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2279" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.3.10-1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7098</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2293" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird \((0\..*|1\.0\..*\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2292" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">(0\..*|1\.0\..*)</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2800" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">1</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.5815.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.8-0.9E</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*ypserv.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2300" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:2.0.1-11</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2299" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2298" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2308" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">17</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2306" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">17</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2305" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">16</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2304" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">17</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2302" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2301" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2311" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:2.3.11-1.9.0</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2310" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*xinetd.*</program_name>
    </inetlisteningservers_state>
    <file_state id="oval:org.mitre.oval:ste:2313" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6823</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2312" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2940" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2938" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <sgid operation="equals" datatype="boolean">true</sgid>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2802" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">2</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2315" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">30983</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2314" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">31732</patch_base>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2318" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.1.6-22.EL3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2317" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2320" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33632</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:2325" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.02.01</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2324" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.02.01</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2323" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.02.01</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2322" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.02.01</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:2804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.893.1105</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:270" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1584</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7102</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2328" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8216</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2330" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.3-8</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2329" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*vsftpd.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2331" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.1.23.1-5</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2805" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.4983</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2332" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.5.2658.34</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2335" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.3.7.2-6</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <owrite operation="equals" datatype="boolean">true</owrite>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2339" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:5.50-33</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2336" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3928" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1698</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">29964</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">28848</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3359" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">B\.11\.11\.(00.*|01\.00[0-5])</version>
    </swlist_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2340" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.11-1</evr>
    </rpminfo_state>
    <uname_state id="oval:org.mitre.oval:ste:3450" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.10</os_release>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:3946" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.20</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:3110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base>23261</patch_base>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3134" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.01</os_release>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:3213" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.30</os_release>
    </uname_state>
    <registry_state id="oval:org.mitre.oval:ste:2810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">RASPHONE.PBK</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2809" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7140</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2808" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.348</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3948" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.327</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2341" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2440</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2345" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.329</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.17-13.3</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2942" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*cupsd.*</program_name>
    </inetlisteningservers_state>
    <patch_state id="oval:org.mitre.oval:ste:2350" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base>32109</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2349" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base>30791</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2348" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base>33589</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2347" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base>31833</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2346" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base>32366</patch_base>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:8.12.8-6.90</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*sendmail.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:8.12.8-9.90</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2359" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">6\.2\.020[5-9]</value>
    </registry_state>
    <swlist_state id="oval:org.mitre.oval:ste:3599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.23</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:3294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33414</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:272" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6972</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:271" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2363" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2362" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2361" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8930</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:44" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8103.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:75" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6815.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2813" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6106</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2364" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.274</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2371" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3809.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2372" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.6756.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6862</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2375" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2377" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2620</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2383" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:8.12.8-5.90</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2382" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2381" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2379" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <sgid operation="equals" datatype="boolean">true</sgid>
    </file_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2378" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*sendmail.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2391" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.10.1-1.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2390" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.10.1-1.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2389" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2388" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2387" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2386" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2393" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.7a-8.9.0</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2392" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*smbd.*</program_name>
    </inetlisteningservers_state>
    <patch_state id="oval:org.mitre.oval:ste:2815" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">2</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2395" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">25</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2394" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">30</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2397" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.747.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.747.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2399" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.7a-7.9.0</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2398" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*smbd.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2816" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.11-0.90.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.552</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:51" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2734</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:22" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2935</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:62" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1860</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:20" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7100</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:273" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2750.166</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:274" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33578</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.118</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.70.11.46</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.70.11.46</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2406" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2411" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:1.1.12-1</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*smtpd.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2820" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.2.0-2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2818" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2817" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:277" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:276" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:275" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.0[12]\..*</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:2412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1400</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2413" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2737.800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4937.800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2415" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3813.800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:279" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.149</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:278" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.158</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:281" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.5.1877.79</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:280" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2807" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2821" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3502.4856</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.44-19.90.0</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2419" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:282" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.0.799</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:288" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:287" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.0.3705.556</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:286" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1,0,3705,2</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:285" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1,0,3705,3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:284" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.0.3705.6021</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:283" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:289" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:3477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2710</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:175" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.588</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2987</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:38" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2783</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:77" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1892</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>6.2.0208</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2360" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>MSN Messenger 6.2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:53" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.559</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:15" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1874</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:125" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7105</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2747</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:64" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2952</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3526.800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2823" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3513.900</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.70.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:292" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.0.390.16</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:291" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.2.2-17.2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2427" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.309.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.760.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:294" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">38</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:293" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">17</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:295" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7329</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2428" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6624</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2825" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7345</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2432" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.0.1200.291</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2431" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2430" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2429" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:297" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.212</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:298" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33566</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:299" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.0.9231</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.803.2</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:300" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3872" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7057</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2937" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">30</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2936" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">6</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:303" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:302" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:301" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:304" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.241</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:305" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.7032</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2435" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3510.1100</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:2.81-88.3</evr>
    </rpminfo_state>
    <patch_state id="oval:org.mitre.oval:ste:2826" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">1</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.6-9.9</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2441" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7044</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2997" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">27</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3089" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">28</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.309</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2447" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-5</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-5</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-5</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6-17</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6b-6</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:307" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.173</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:306" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.184</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:71" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1873</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:19" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2951</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:310" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">25</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:309" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">19</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:308" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6713</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.0.0.3</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:311" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.842</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:312" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.205</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2454" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.5p1-11</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2456" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.5p1-6.9</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2455" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*sshd.*</program_name>
    </inetlisteningservers_state>
    <patch_state id="oval:org.mitre.oval:ste:316" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:315" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:314" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:313" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.1-3.9</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*rpc\.mountd.*</program_name>
    </inetlisteningservers_state>
    <file_state id="oval:org.mitre.oval:ste:12" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2962</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:13" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2757</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2459" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1710</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2831" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.2103</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2830" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:317" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:319" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.0.1044</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:318" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:320" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">12</version>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">B\.11\.00\.(00.*|01\.00[0-4])</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:321" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2452" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2525</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2461" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.23.56-1.9</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2460" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*mysqld.*</program_name>
    </inetlisteningservers_state>
    <file_state id="oval:org.mitre.oval:ste:185" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1829</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:137" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7084</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:139" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2889</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:21" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.520</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2684</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:322" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.6970</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2465" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">5:1.4.1-1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2464" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2463" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2462" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2761" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:323" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6946</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8950</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:132" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8104.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:25" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8105.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:24" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6816.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2466" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.49.4-9.9.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2467" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.2609.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:324" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33587</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.588</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:52" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2783</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1885</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:31" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7106</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:32" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2974</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:325" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.198</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:327" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.0.1200.408</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:326" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">KB888258</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:328" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.205</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.33668.1</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:3.8.19-3.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*lpd.*</program_name>
    </inetlisteningservers_state>
    <file_state id="oval:org.mitre.oval:ste:329" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1411</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33412</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <inetd_state id="oval:org.mitre.oval:ste:2935" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/dt/bin/rpc.cmsd</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2933" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2932" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2931" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2834" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">22</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2833" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">6</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:332" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:331" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:330" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">6:3.1-12</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2479" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2478" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">34077</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3434" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.04</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:2839" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">1</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:2838" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/lib/netsvc/rwall/rpc.rwalld</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2837" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2836" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2835" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:335" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">13</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:334" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:333" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.280</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.0.1200.257</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.0.1200.257</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">331066</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2483" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">2</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:341" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:340" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:339" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:338" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:337" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:336" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7023</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.6981.3</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:345" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:344" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:347" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33591</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:348" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1363</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:72" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8951</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:68" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8104.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:43" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8106.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:27" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:349" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7323</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2974" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">12</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3522" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3074" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3679" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.7</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:3846" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">13</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3272" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2988" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2965" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3688" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3041" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">20</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3585" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:350" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">16</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:351" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7270</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2734.1600</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:352" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.198</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:353" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>10.0.4330.0</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:355" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:354" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:357" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1580</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:356" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1580</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>11.0.5614.0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2494" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2427</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2841" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.4980</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2840" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:359" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:360" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4945.2800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:33" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.0.50727.210</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3045" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2695</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1498</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1499</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2500" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3669.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3644.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3644.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3644.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2496" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2801" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6672</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2846" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.764.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.4205.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.4205.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:364" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:1.2.2-24</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:363" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">2:1.2.2-24</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:362" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.13-14</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:361" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.13-14</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2504" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.2.7523</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.2.7523</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:366" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">18</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:365" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:369" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.72.3841.1100</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:372" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">14</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:371" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:370" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3473" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <package_state id="oval:org.mitre.oval:ste:3088" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="pattern match">7\.0,.*</version>
      <description operation="pattern match">7\.0,.*</description>
    </package_state>
    <file_state id="oval:org.mitre.oval:ste:374" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.7036</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:373" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:375" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.242</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.5-4.RHEL3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2505" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:377" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.1.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.12.5118.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.250</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:379" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="equals" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:378" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:384" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1,0,4322,0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:383" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.1.4322.2037</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:382" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:381" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.1.4322.1085</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:380" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:385" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1634</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:3311" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.00</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3127" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.00</version>
    </swlist_state>
    <uname_state id="oval:org.mitre.oval:ste:3695" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.10</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:3260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base>23262</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:3442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.10</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.10</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:386" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2600.151</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:387" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:388" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.94</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:392" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:391" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:390" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.117</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:389" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1243</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:34" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6811.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:17" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8948</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8036.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:394" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.0.9232</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:395" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:3006" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2465</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:4.3.2-24.ent</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1276</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4934.1600</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.71.2195.6920</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3810.1700</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:399" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:398" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:397" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6799</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2849" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">1</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2848" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2847" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:401" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.112</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:400" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1193</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.82.2800.1891</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:73" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.82.3790.583</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:198" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.82.3790.2778</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:41" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.82.2900.2982</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:94" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.81.3900.7109</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:402" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.6922</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:403" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2742.200</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1215" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">6,0,2600,0000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8216</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7342</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2515" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3523.1700</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2517" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.3881</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2516" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>10.0.6626.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:405" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>11.0.3216.5614</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:404" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3264.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:406" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">Installed</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7312</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2518" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2520" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2709</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2850" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">38</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:411" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1567</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:410" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1567</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1555</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1555</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:412" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7017</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2522" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.4490</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2521" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.225</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:413" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.227</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2524" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7224</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2523" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:14" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1873</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2951</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.559</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:135" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.7105</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:37" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2746</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2526" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.650.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:415" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6159</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.233</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:418" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6952</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:417" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6922</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">30302</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">30006</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2858" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">2</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2856" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:419" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33630</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:422" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:421" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1233</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2600.115</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2529" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.2.7523</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2527" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:423" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:425" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7286</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33577</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:426" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1613</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2530" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-19.9</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:427" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6714.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.4905</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2860" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:133" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.526</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:6" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7087</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:122" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1832</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:157" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2691</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2893</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2532" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2531" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:430" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:429" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:428" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:432" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:431" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3374" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3922" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6753</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2250" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2604</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.6.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.62.9119.1</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:435" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">6</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:434" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="less than" datatype="int">3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:433" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version"/>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2789" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2539" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.650.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2864" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5671</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2863" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:436" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1619</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.9.1121</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2540" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:437" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6929</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-18.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:440" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-15.0.2.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:439" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-15.0.2.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:438" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-15.0.2.EL</evr>
    </rpminfo_state>
    <patch_state id="oval:org.mitre.oval:ste:441" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">8.0.0.4477</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2547" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.9.1121</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.9.1124</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2545" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.4482</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.4482</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:11.6.0-11.90</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2865" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:11.6.0-11.90</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8028.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6804.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:35" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8944</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2551" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6110</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:442" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6966</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>10.2.5110</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:443" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33618</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.53.6202.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2536" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.5.*$</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:447" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2553" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.578.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.561.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3264.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:450" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^5\.[1-2]$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:85" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2975</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:124" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1886</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:40" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.576</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:39" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2771</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2869" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.3314.2101</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3504.2500</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2204" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.336</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2557" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.120</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2556" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1301</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.120</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2554" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1301</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:453" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2003.1100.6252.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:452" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">9.00.9327</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:451" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">9.00.9327</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:3812" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1711</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>ia64</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:458" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.181</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:457" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.185</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:1.3.1-0.el3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:459" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6011</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2563" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.20-13.9</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2877" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5974</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:462" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:461" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:460" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:466" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:465" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:464" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:463" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2567" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.324</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:467" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.245</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2247" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.227</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:468" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7021</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2321" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2319" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2208" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7035</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2696</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2951" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Service Pack 2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:469" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.279</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3777" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">12</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3539" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3535" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">13</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3220" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:470" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2563</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:471" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7005</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <release operation="equals">6</release>
      <version operation="equals">2.4.20</version>
    </rpminfo_state>
    <uname_state id="oval:org.mitre.oval:ste:2573" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release operation="equals">2.4.20-6</os_release>
    </uname_state>
    <file_state id="oval:org.mitre.oval:ste:473" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3534.2800</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:472" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:479" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:478" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:477" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:476" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:475" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:474" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2575" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:480" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.163</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7299</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:481" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:485" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6928</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.0.0.5</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:483" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int"/>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2577" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.7-14</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2576" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.7-14</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2580" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.206</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2579" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2578" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:487" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.219</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:486" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1596</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:494" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">24</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:493" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:492" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.163</version>
    </file_state>
    <metabase_state id="oval:org.mitre.oval:ste:2879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <data operation="not equal">4</data>
    </metabase_state>
    <file_state id="oval:org.mitre.oval:ste:497" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7268</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:496" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7280</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:498" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.168</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:499" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1.1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.0.1.2125</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.811.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2594" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.818.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.816.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2592" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.800.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.778.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2589" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.798.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2588" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2587" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.765.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:501" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6735.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:500" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">10.0.8326.0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:503" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.109</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8946</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:183" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6809.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:174" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8033.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:449" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>11.0.6252.7</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.536</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2912</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:92" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7085</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:121" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1847</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:171" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2706</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">2000.80.384.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2605" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.223.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2604" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.223.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2603" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.223.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.223.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:505" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.211</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:504" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2859" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2581" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">65</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.7-14</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4725.2100</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:507" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2577</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:506" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:509" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7304</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:508" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:511" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">5.1.0639</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:510" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.0.639</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:195" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int" operation="equals">6</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int" operation="equals">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:512" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33545</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3826.2400</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:513" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4922.900</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:527" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:526" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:525" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:524" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">14</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:523" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:522" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:521" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:520" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:519" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:518" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:517" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:516" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:515" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:528" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1556</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:531" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:530" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:529" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:65" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8107.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">11.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8950</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">9.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:29" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6817.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:7" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">10.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:534" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2745.2800</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:533" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:532" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8929</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:199" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.10.2930.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:60" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.20.9839.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:28" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.70.1113.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3888.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:9" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6819.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:23" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8110.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:56" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8952</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:549" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3677.144</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:548" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.08\.02.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:547" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:546" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.3.0.903</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:545" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.09.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:544" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:543" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.148</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:542" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.08\.01.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:541" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:540" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1517</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:3839" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.10</os_release>
    </uname_state>
    <isainfo_state id="oval:org.mitre.oval:ste:3528" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <bits>64</bits>
    </isainfo_state>
    <uname_state id="oval:org.mitre.oval:ste:3040" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <processor_type operation="pattern match">^i.*86</processor_type>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:3384" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">14</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2202" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:550" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1643</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:551" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2609" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.5.132</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.80</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:554" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:553" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33567</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:552" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7269</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:556" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:555" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="pattern match" datatype="string">^.*smbd.*</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3819.300</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:557" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">15</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4942.400</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2618" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6861</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2617" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6861</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2616" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2615" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.220</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:560" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6945</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:3324" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.23</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:3930" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">32606</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6754.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2583" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4943.400</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:5" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">9\..*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:96" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2003.1100.8020.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:563" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:562" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2453" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3821.2800</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2620" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.191</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2619" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8943</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:568" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">13</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:567" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="equals" datatype="int">12</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1597</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2868" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.3315.1000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2623" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3532.300</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2624" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.6328</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.7009</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.7233.69</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:573" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:572" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2625" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.6926</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:575" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.5.2558.10</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:574" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">2</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2333" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>2653</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:578" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:577" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">13</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:576" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2630" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.118</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2629" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1255</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2628" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2626" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:582" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">16</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:581" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:580" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:579" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2888" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6810</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2947" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.6-2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2946" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2944" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:584" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.137</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:583" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1364</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:585" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.7650.29</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2636" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2635" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5880</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2633" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8942</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:588" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:587" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.2195.6758</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:589" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1836</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:590" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.3704</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:592" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/sbin/in.ftpd</server_program>
    </inetd_state>
    <registry_state id="oval:org.mitre.oval:ste:2803" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.3645</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <metabase_state id="oval:org.mitre.oval:ste:2638" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <data operation="pattern match">^.*idq\.dll.*$</data>
    </metabase_state>
    <file_state id="oval:org.mitre.oval:ste:594" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.155</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:593" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1564</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:595" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.1280</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:596" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.142</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:597" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1606</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:600" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1441</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:599" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:598" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2641" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7224</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2646" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">6:3.1-15</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2645" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2644" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2643" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2647" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:601" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2001.12.4414.311</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2829" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2648" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.2784</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:602" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1842</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:605" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">12</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:604" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">19</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:603" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.3659.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2650" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2649" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2716.2200</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:606" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version">5.0.44.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2654" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5971</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2653" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2652" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:607" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1620</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1605</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:609" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2655" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.7924</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1560</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:613" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33565</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:612" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33574</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:611" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7097</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2663" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.2600.117</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2661" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.2600.1243</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2660" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2659" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2658" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:615" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.252</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:617" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:616" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:618" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.166</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:619" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2902</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:627" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">14</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:626" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">51</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:625" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:624" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:623" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">14</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:622" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">51</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:621" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:620" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:629" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1580</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:628" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1580</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:631" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:630" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6800.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:632" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2908</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:633" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.3349</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2665" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.776.1</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2664" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:634" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.6618.4</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:635" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1254</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:636" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6902</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:637" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.4496</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:638" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.3704</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [4-9]|\d{2,}$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:3781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7055</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2893" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7116</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.6502.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2416" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2743.600</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:640" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.529</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1484" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2663</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:643" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">1.8.20060.42618</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:642" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Mozilla Firefox (1.5.0.2)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:641" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.5\.0\.2 .*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <sgid operation="equals" datatype="boolean">true</sgid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2666" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:644" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7087</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:645" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">5.6.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:647" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1555</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:646" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="binary">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:649" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^5,50,.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:648" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4963.1700</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4134.0100</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4134.0600</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4522.1800</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2822" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4923.2500</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:655" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.53.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:654" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.53.6306.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:653" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.71.9053.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:652" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.80.1062.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:651" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.81.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:650" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.81.1124.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2231" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.71.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2213" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.8.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:656" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.537</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:657" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.504</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2668" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">20</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:658" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2663</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:659" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.503</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:660" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7085</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:662" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">34544</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:661" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">B\.11\.11\.(00.*|01\.00[0-7])</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:3269" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33395</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:663" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">34545</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:664" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.198</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2206" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:669" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:668" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.72.3843.3100</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:667" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7267</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:666" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.3356</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:665" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:670" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6790.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:671" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2662</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:672" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.82.2644.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:673" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7093</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:3011" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:3226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:3819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base>23263</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6802.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3528.700</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:678" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">14</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:677" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">09</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:676" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:679" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.4036</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.3102.1355</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.529</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7265</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:682" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33563</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:684" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2709</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:26" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2963</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:36" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1561</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:149" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2759</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:11" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.554</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:178" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3842.3000</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:685" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:686" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.0.9232</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3850" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3228" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3562" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3405" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3667" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3869" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2713.1100</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:688" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">14</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:687" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">17</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:689" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2627</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">32149</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">32926</patch_base>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2670" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.40-21.5</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2669" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*httpd\.worker.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">([0-7]|8\.([0-9]|1[01]))</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">8\.12\.([0-9]|10)</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">8\.13\.[0-5]</version>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1693</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2685</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:698" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">27</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:697" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">12</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1807</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1816</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2672" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.326</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">106.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.2600.3</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1792</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">9.0.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.3344</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">33214</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">33215</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2559" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2622</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2403" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.224</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:708" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.3790.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2278" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2617</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.0.12512</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2678" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-33.15</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2677" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-33.15</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2676" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-33.15</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2675" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6b-16.22.3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2674" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3837.1200</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.22</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">29462</patch_base>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:502" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>10.0.8326.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2179" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*-OEM-.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:30" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2003.1100.8029.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:719" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:718" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:717" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:716" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">06</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:715" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:714" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1555</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:726" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">33</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:725" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">22</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:724" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">29</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:723" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">33</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:722" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">22</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:721" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">29</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:733" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:732" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:731" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:730" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:729" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:728" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:727" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:734" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.462</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2869</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1485" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^6,0,.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7134</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:736" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2912</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:737" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">24</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:2257" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">24</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33159</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2598</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:739" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1609</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>C:\Program Files\Windows NT\hypertrm.exe /t %1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2821</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">Windows ME</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:3591" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:3916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2477</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:3833" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Service Pack 1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">10\.0+\..*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.0.4019</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.2.2551.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">106.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2680" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7092</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2697</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">32280</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2892</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>C.04.00.00.00</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>C.04.01.00.00</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.220</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:757" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:756" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2786" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2681" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7152</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:758" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">7.10.0.3077</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:759" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">29249</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:761" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.23</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:760" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33792</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:2316" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.23</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:764" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:763" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:762" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">33967</patch_base>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:765" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1.1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1789</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1476</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:767" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:769" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6992</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:770" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.0.2.629</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:771" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">7.0.19.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:772" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8936</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8938</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:775" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2534</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7099</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.556</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2945</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:192" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1869</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2741</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.239</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:776" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="binary">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2253" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:778" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.453</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:779" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.386</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:780" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A(\.0[0-3]\..*|\.04\.[0-1].*|\.04\.20\.00[0-3])</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:782" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1522</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:781" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1523</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:783" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.413</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:784" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7065</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:785" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3833.200</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:789" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:788" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:787" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:786" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:790" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2743</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:791" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:792" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8012.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2682" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">6</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:793" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2744</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:794" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2763</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:795" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.2.4.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:796" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6902</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:797" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.71.9053.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8012.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2684" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.0.40-21.1</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:2683" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*httpd.*</program_name>
    </inetlisteningservers_state>
    <patch_state id="oval:org.mitre.oval:ste:2909" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">9</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2907" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2906" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2905" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:799" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34163</patch_base>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2290" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox \((0\..*|1\.0\..*\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2289" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">(0\..*|1\.0\..*)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2286" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2285" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla \(.*\)</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:801" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1762</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:800" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1762</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2689" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">3</version>
    </patch_state>
    <inetd_state id="oval:org.mitre.oval:ste:2688" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/openwin/lib/fs.auto</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2687" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2686" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2685" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:802" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3835.2200</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:804" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*OFFICE9.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:803" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.5.3201.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:805" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1831</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:807" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:806" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2693" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.9-0.9.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2692" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2691" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2690" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:808" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2001.12.4720.480</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:812" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.20</os_release>
    </uname_state>
    <swlist_state id="oval:org.mitre.oval:ste:811" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.10.20</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:810" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.10.20</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:809" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">23948</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:816" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:815" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:814" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:813" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version datatype="int">01</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2892" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2694" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3502.4718</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:817" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2769</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:818" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:819" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34102</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:820" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2606</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2696" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2695" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7214</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:824" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:823" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:822" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:821" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.01\.(0.*|10.*|11[^\.]|11\.0[0-3])</version>
    </swlist_state>
    <registry_state id="oval:org.mitre.oval:ste:826" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*OFFICE11.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:825" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">11.0.6566.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.418</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:828" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">30402</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2698" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7125</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2697" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:829" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2869</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:831" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">5\.0\..*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:830" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3839.2200</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:837" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:836" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:835" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:834" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:833" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:832" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2774" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2699" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.4919</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:838" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">23950</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">6.4.2600.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:842" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.2600.1738</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2818</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7073</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2700" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2722.900</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:848" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.00</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:847" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.00</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:846" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">33989</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:850" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2600.1579</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:849" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2600.165</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:851" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2827</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:853" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">6.4.3790.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:852" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.4.3790.399</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:854" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.536</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:855" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.3940.42</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2703" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2702" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7203</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:856" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8026.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:857" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33598</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:858" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1724</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:859" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3841.1900</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.374</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:860" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.374</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">33219</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6789.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2875" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.2919.800</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.2919.3800</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2873" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.2919.6307</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2872" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.2920.0000</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.3103.1000</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2870" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.00.3105.0106</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2708" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3214.2000</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2707" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2706" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2705" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2704" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:863" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:865" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.([01].*|2\.00\.00)</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:864" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A\.0[12]\..*</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:1300" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">32606</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:866" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.1002.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:868" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [1-9]|\d{2,}$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:867" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.346</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:869" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than or equal">5.1.2.275</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2709" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2912" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">52</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2911" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <sgid operation="equals" datatype="boolean">true</sgid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2910" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2773" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7064</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2711" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7097</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2713" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.9-0.9</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3810.0</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2717" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.1-4</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2716" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2715" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:871" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:870" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.233</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:873" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.1-1</evr>
    </rpminfo_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:872" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">.*/radiusd</program_name>
    </inetlisteningservers_state>
    <swlist_state id="oval:org.mitre.oval:ste:2236" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">(((A|B)\.2\.0\.55\.\d+)|((A|B)\.[3-9]\..*)|((A|B)\.[1-9]\d+\..*)|((A|B)\.2\.[1-9]\d*\..*)|((A|B)\.2\.\d+\.[6-9]\d+\..*)|((A|B)\.2\.\d+\.5[6-9]\d*\..*)|((A|B)\.2\.\d+\.\d{3,}\..*))</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:875" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.71.1979.1</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:874" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1327" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [6-9]|\d{2,}$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2723" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.0.8513</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2722" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.5.0.8513</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2721" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.6.0.8513</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2720" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5,6,0,8513</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2719" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5,1,0,8513</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2718" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5,5,0,8513</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2291" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">1.8.20060.11112</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:877" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.259</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:876" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:879" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">34543</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">B\.11\.11\.(00.*|01\.00[0-5])</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:880" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.1558.6608</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:881" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8930</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:883" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6958</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:882" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2768" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2727" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.05-32.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2726" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2725" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2724" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:884" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1734</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2488" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3831.1800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:885" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.80.1062.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:886" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7268</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2451" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2256" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^.*ServerNT.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2901" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.775.1</version>
    </file_state>
    <metabase_state id="oval:org.mitre.oval:ste:2897" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <data operation="pattern match">^.*asp\.dll.*$</data>
    </metabase_state>
    <file_state id="oval:org.mitre.oval:ste:888" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">5.0.1460.9</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:887" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.1462.22</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>6249</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.6618.4</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:891" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.468</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2728" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">30</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:892" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3825.700</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:895" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">9.00.00.2980</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:894" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.3250</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:893" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">1.1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2627" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:896" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1617</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2900" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2885" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5269</version>
    </file_state>
    <metabase_state id="oval:org.mitre.oval:ste:2862" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <data operation="pattern match">^.*ism\.dll.*$</data>
    </metabase_state>
    <file_state id="oval:org.mitre.oval:ste:110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.558</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2744</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:897" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2802</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.366</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2001.12.4414.65</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:901" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:900" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2184" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1543</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:902" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7061</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2203" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:903" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7035</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:905" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.22</os_release>
    </uname_state>
    <swlist_state id="oval:org.mitre.oval:ste:904" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">((1\.7\.12\..*)|(1\.(([8-9])|(\d{2,}))\..*)|(1\.7\.((1[3-9])|([2-9]\d+))\..*))</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:906" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.383</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:907" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7054</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1207" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">Windows 98</value>
    </registry_state>
    <uname_state id="oval:org.mitre.oval:ste:2352" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.00</os_release>
    </uname_state>
    <swlist_state id="oval:org.mitre.oval:ste:2226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.00</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:2225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.00</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">23949</patch_base>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2558" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.280</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">6.1.9.726</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:915" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.9.732</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Mozilla Firefox (1.0.7)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:917" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.0\.7 .*</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">34306</patch_base>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2701" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:920" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="equals">5.1.2600.1151</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2281" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.419</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:921" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">A(\.0[0-3]\..*|\.04\.[0-1].*|\.04\.20\.00[0-4])</version>
    </swlist_state>
    <file_state id="oval:org.mitre.oval:ste:2814" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2723.2500</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2326" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">37:1.7.10-1.1.3.1</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">8\.0\.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.4495</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:924" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.1673</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:925" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1733</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2401" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7059</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2400" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7059</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:926" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.396</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:927" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34123</patch_base>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:2.2.2-4rhel3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:928" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:930" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7069</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:932" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.6.7p5-1.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:931" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:933" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6991</version>
    </file_state>
    <inetd_state id="oval:org.mitre.oval:ste:2855" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/lib/fs/cachefs/cachefsd</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2854" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2853" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2852" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2832" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3828.2700</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2192" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34169</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:948" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.04.70</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:947" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.04.70</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:946" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34121</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:945" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.04.60</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:944" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34170</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:943" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.04.60</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:942" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34120</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:941" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.04.50</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:940" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34171</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:939" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.04.50</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:938" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34119</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:937" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.02.10</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:936" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34203</patch_base>
    </patch_state>
    <swlist_state id="oval:org.mitre.oval:ste:935" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>A.02.00</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:934" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">34204</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.6506.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:950" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">6.5.2600.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:949" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.2600.2749</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:952" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">7.1.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:951" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">7.10.0.3076</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2734" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1264</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2731" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">.hta</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:954" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:953" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:955" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.5.0.117</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:956" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.2.3535.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2591</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2621" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>6.00.3790.0000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2187" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.373</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2491</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2262" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2542</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:957" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7057</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:959" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.10.24</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:958" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">24395</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:960" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2736</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2791" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">8.00.194</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2742" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.608.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2741" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2740" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2739" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2738" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2736" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.628.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2215" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1505</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2214" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1506</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:961" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.81.1124.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2729" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">Y</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:962" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.76</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:963" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.6617.86</version>
    </file_state>
    <inetd_state id="oval:org.mitre.oval:ste:2746" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/openwin/bin/kcms_server</server_program>
    </inetd_state>
    <file_state id="oval:org.mitre.oval:ste:2745" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2744" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2743" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2925" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4913.1100</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2924" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2923" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:965" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3539.2400</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:964" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:967" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.8.4-12.3.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:966" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.8.4-12.3.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2272" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.0.0.3423</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2271" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.1241</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:968" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.7071</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:969" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3900.7078</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:970" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6764.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2288" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox \(1\.5\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2287" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.5($|\s).*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:978" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">1.8.20060.30804</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:977" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Mozilla Firefox (1.5.0.1)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:976" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.5\.0\.1 .*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:975" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.5($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:974" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird \(1\.5\)</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:973" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">1.8.20060.30803</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:972" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">(1\.0[ab].*|1\.0[^\.].*)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:971" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">SeaMonkey \((1\.0[ab]|1\.0)\)</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1265" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.185</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1264" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:980" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2549</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:979" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2549</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:981" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2595</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2748" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6699</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2747" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:982" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.507</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3712" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33159</patch_base>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3389" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.11</os_release>
    </uname_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:984" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:1.8.17-9.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:983" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:1.8.17-9.2</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2750" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2749" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">816456</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2490" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2489" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2268" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:986" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:985" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2004.10.25.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:988" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*OFFICE10.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:987" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6772.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3645" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">14</version>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3443" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <processor_type operation="pattern match">^i.*86</processor_type>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:3597" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.10</os_release>
    </uname_state>
    <registry_state id="oval:org.mitre.oval:ste:990" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>7226</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:989" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.7233.69</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:3724" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3291" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3700" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.8</os_release>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:3478" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <processor_type operation="pattern match">[Ss][Pp][Aa][Rr][Cc]</processor_type>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:3891" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.9</os_release>
    </uname_state>
    <registry_state id="oval:org.mitre.oval:ste:1342" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:991" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7021</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:992" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8938</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:995" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2541</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2234" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:997" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1755</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:996" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1331</version>
    </file_state>
    <swlist_state id="oval:org.mitre.oval:ste:1000" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:999" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.11</version>
    </swlist_state>
    <patch_state id="oval:org.mitre.oval:ste:998" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33791</patch_base>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2748</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:18" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.560</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1004" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">6.5.3790.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1003" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.3790.2519</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1002" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.3.1.889</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1001" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.[0]*9\..*</value>
    </registry_state>
    <uname_state id="oval:org.mitre.oval:ste:2354" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.11</os_release>
    </uname_state>
    <swlist_state id="oval:org.mitre.oval:ste:1005" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version operation="pattern match">B\.11\.00\.(00.*|01\.00[0-3])</version>
    </swlist_state>
    <registry_state id="oval:org.mitre.oval:ste:2402" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Service Pack 4</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1006" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4956.500</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2440" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">Microsoft ISA Server 2000 Updates</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2439" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.0.1200.430</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2438" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">KB899753</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1007" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2666</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2566" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2437</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1009" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1683</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1008" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2673</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2266" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1515</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2265" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1516</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1010" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:2806" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">19</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1012" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:0.17-20.EL3.3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1011" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1013" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2697</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2374" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2492</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2373" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2492</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1015" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2726</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1014" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2726</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2622" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2586" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1458</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2344" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2442</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2343" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1016" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1684</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1017" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.6749.0</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:1020" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1019" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1018" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:1022" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.426</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1021" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.426</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2519" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1023" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.359</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1024" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.2.5-6.el4.2</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1025" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2770</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2751" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">1:2.4.1.3-5.1</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2887" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2730" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6802</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2610" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [5-9]|\d{2,}$</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1028" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-32.0.1.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1027" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-32.0.1.EL</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1026" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-32.0.1.EL</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1029" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1751</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2570" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>CoPNGFilter Class</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1030" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2668</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1032" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.0.9231</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1031" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:3608" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">33427</patch_base>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3271" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.04</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:1036" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1035" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1034" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1033" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">07</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2491" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.3.3-12.rhel3</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1037" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1038" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1727</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1039" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.121</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1041" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.[0]*9\.[0]+\.[0]*900</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1040" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.[0]*9\.[0]+\.[0]*901</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1042" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2577</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2927" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">16</version>
    </patch_state>
    <process_state id="oval:org.mitre.oval:ste:2934" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <user_id operation="equals">root</user_id>
    </process_state>
    <inetd_state id="oval:org.mitre.oval:ste:2908" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <server_program operation="equals" datatype="string">/usr/dt/bin/rpc.ttdbserverd</server_program>
    </inetd_state>
    <patch_state id="oval:org.mitre.oval:ste:1043" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:2351" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.23</os_release>
    </uname_state>
    <file_state id="oval:org.mitre.oval:ste:2238" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1528</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1324" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4134.0100</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1323" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4134.0600</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1322" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4522.1800</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1319" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1045" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4616.200</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1044" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4701.2400</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1047" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.[0]*8\..*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1046" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2926" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">5.50.4807.2300</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1312" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4926.2500</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1363" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.132</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1358" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1051" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">6\..*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1050" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.449</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1049" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1048" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2753" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6685</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2752" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2370" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-9]\)|\(1\.7\.10\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2369" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">([0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-8]($|\s).*|1\.7\.10($|\s).*)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2368" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">(0\.[0-9].*|1\.0($|\s).*|1\.0\.[1-6]($|\s).*)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2367" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-6]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2671" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1368" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5,50,4807,1700</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1052" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.50.4952.2800</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1053" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:7.3.10-1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1055" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">6.0.6603.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1054" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.6617.47</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2235" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.0.2-11.EL3.4</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1056" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1059" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Windows.*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1058" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1057" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1060" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2706</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1062" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.636.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1061" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.636.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1063" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6905</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1068" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1715</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1067" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2716</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1066" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2483</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1065" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1064" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:1070" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1069" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2477" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">^.*4.S</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2476" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">37:1.7.10-1.4.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:2475" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1071" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2001.12.4414.53</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1073" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1720</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1072" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1720</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1075" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>7638</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1074" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.5.7650.28</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2754" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.2.2-5</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1076" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8024.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1077" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.2956</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1078" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.6.0.8831</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1079" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2001.12.4720.130</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1095" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.1.0-15.EL</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1094" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1093" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1092" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1091" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1090" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1089" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1088" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1087" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1086" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1085" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1084" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1083" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1082" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1081" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1080" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1097" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.132</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1096" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1331</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1099" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7069</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1098" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6898</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1100" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.2.3511.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2251" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>6.0.2900.2180</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2183" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2722</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1101" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.1558.6072</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2565" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>x64</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2495" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.315</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2435</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1102" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2453</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1104" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.131.2600.1123</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1103" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="binary">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1351" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1106" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.128</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1105" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1343</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1110" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2750.167</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1109" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1584</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1108" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1107" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*zipfldr\.dll.*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1111" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^([1-5]\.[0-9].*|6\.(0.*|1|1\.([0-9]($|\..*)|[0-1][0-9]($|\..*)|20($|\..*)|21($|\..*))))$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2828" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1112" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.3649</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1341" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-20.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1340" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-20.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1339" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.7a-20.2</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1338" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6-25.9</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1337" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.6b-15</evr>
    </rpminfo_state>
    <patch_state id="oval:org.mitre.oval:ste:1114" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">18</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1113" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">15</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:1115" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">1.0.0.4</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1118" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [0-4]$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1117" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7059</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1116" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <patch_state id="oval:org.mitre.oval:ste:1124" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">94</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1123" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">52</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1122" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1121" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">83</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1120" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">41</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:1119" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">08</version>
    </patch_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1125" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.11.2-18</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1127" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7263</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1126" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.33562</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1257" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1130" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.81.9001.40</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1129" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.81.9041.40</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1128" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.7.*</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2327" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">^.*3.S</version>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1132" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:6.2.0-3.el3.1</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1131" version="1" operator="OR" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
      <gexec operation="equals" datatype="boolean">true</gexec>
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2284" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">SeaMonkey \(1\.0[ab]\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2283" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.0[ab].*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1138" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-7]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1137" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">(0\.[0-9].*|1\.0($|\s).*|1\.0\.[1-7]($|\s).*)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1136" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\)|\(1\.0\.[0-7]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1135" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-7]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1134" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">([0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-8]($|\s).*|1\.7\.1[0-2]($|\s).*)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1133" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-9]\)|\(1\.7\.1[0-2]\))</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1141" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.161</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:3073" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <machine_class operation="pattern match">\d+/8\d+</machine_class>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:3737" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>CO</area_patched>
      <patch_base operation="greater than or equal">28847</patch_base>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:3919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>SS</area_patched>
      <patch_base operation="greater than or equal">29963</patch_base>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:3813" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.00</os_release>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:3773" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <machine_class operation="pattern match">\d+/7\d+</machine_class>
    </uname_state>
    <registry_state id="oval:org.mitre.oval:ste:2525" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>WinNT</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1354" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1245" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Y</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1143" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.137</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1142" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.141</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2757" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7202</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2756" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2755" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">4</value>
    </registry_state>
    <uname_state id="oval:org.mitre.oval:ste:2355" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <machine_class operation="pattern match">\d+/7\d+</machine_class>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:2353" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <machine_class operation="pattern match">\d+/8\d+</machine_class>
    </uname_state>
    <swlist_state id="oval:org.mitre.oval:ste:1148" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.04</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:1147" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.04</version>
    </swlist_state>
    <swlist_state id="oval:org.mitre.oval:ste:1146" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <version>B.11.04</version>
    </swlist_state>
    <uname_state id="oval:org.mitre.oval:ste:1145" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>B.11.04</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:1144" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux">
      <swtype>PH</swtype>
      <area_patched>NE</area_patched>
      <patch_base operation="greater than or equal">24395</patch_base>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2673" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">6,0,3790,0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1150" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.137</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1149" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1165" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.07.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1164" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6927</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1163" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1162" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.08\.00.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1161" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2258.410</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1160" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1159" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.08\.01.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1158" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.891</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1157" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1156" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.08\.02.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1155" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3677.144</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1154" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1153" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^4\.09\.00.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1152" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.3.0.903</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1151" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2824" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.00.3502.1000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2572" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3541.2700</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2571" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2424" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">8.00.194</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1172" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.650.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1171" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1170" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1169" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1168" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1167" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.606.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1166" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.628.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1175" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1174" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1173" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2884" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [3-9]|\d{2,}$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1177" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Microsoft Exchange 2000</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1176" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.5700.21</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2902" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Terminal Server</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2894" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">4.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2843" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1179" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.0.1381.7058</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1178" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2873</version>
    </file_state>
    <patch_state id="oval:org.mitre.oval:ste:2758" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">2</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2904" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">4</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2845" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2844" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1180" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">4.2.764.1</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1181" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-15.EL</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2842" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^.*LanmanNT.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1365" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.6902</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1184" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [0-2]$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1183" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2578</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1182" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2922" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2921" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2920" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2919" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2918" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2917" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2916" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2915" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2914" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2913" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2895" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^6\.0+\.2600\.0+$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2421" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1318" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2712.300</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1317" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1316" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1315" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1314" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1313" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1204" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:2.4.21-15.EL</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2903" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1305" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.5807</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1366" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>6,0,2800,1106</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1185" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1409</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2949" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="equals">9</version>
    </rpminfo_state>
    <uname_state id="oval:org.mitre.oval:ste:2948" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <machine_class operation="pattern match">^i.*86</machine_class>
    </uname_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2798" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.13-1.90.1</evr>
    </rpminfo_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2797" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:0.9.13-1.90.1</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2899" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2898" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2886" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int" operation="equals">5</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int" operation="equals">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1125</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1188" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.137</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1187" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1515</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1186" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1190" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.137</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1189" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1362</version>
    </file_state>
    <inetlisteningservers_state id="oval:org.mitre.oval:ste:1482" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <program_name operation="pattern match">^.*httpd.*</program_name>
    </inetlisteningservers_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1191" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.4.3-0.e3.1</evr>
    </rpminfo_state>
    <registry_state id="oval:org.mitre.oval:ste:2766" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2735" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>6.00.2800.1106</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2733" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2732" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2632" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2631" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="not equal" datatype="int">3</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1193" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1491</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1192" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1492</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1195" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.136</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1194" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1363</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:2303" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.10</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:207" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:206" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:205" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:204" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">10</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:203" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:202" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">11</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:201" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:200" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">01</version>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:2851" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.7</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:211" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:210" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">03</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:209" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">38</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:208" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">27</version>
    </patch_state>
    <uname_state id="oval:org.mitre.oval:ste:2857" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.9</os_release>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:2309" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <processor_type operation="pattern match">[Ss][Pp][Aa][Rr][Cc]</processor_type>
    </uname_state>
    <uname_state id="oval:org.mitre.oval:ste:2307" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <processor_type operation="pattern match">^i.*86</processor_type>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:215" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:214" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">02</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:213" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">05</version>
    </patch_state>
    <patch_state id="oval:org.mitre.oval:ste:212" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">04</version>
    </patch_state>
    <registry_state id="oval:org.mitre.oval:ste:2282" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:216" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.347</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:217" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2464</version>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:2679" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <version operation="pattern match">^3.S</version>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:1243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <uexec operation="equals" datatype="boolean">true</uexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <gexec operation="equals" datatype="boolean">true</gexec>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1241" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <rpminfo_state id="oval:org.mitre.oval:ste:1209" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux">
      <evr datatype="evr_string" operation="less than">0:1.11.2-24</evr>
    </rpminfo_state>
    <file_state id="oval:org.mitre.oval:ste:218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2698</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:219" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1701</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2890" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2889" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [4-9]|\d{2,}$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:220" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.2195.7053</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:221" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2465</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:222" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2483</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2827" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Service Pack 2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:223" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.2716</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:224" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1715</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2582" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:225" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2491</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:226" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1699</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:227" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.2.3790.2477</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:231" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">0\.9($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:230" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox \(0\.9.*\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:229" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">0\.[6-8]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:228" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird \(0\.[6-8]\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:233" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-4]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:232" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-4]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:235" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">0\.[0-8]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:234" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird \(0\.[0-8]\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:239" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">0\.[6-9]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:238" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird \(0\.[6-9]\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:237" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">1\.7($|\s).*|1\.7\.[0-3]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:236" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\(1\.7\)|\(1\.[0-7]\.[0-3]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:241" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">0\.[0-9]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:240" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox \(0\.[0-9].*\)</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:243" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:242" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:247" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:246" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:245" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-5]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:244" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-5]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:249" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-1]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:248" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-1]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:251" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-6]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:250" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-6]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:253" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-3]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:252" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-7]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:255" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-2]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:254" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Thunderbird (\(0\.[0-9]\)|\(1\.0\)|\(1\.0\.[0-2]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:257" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-2]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:256" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-2]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:261" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-4]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:260" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla Firefox (\(0\.[0-9].*\)|\(1\.0\)|\(1\.0\.[0-4]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:259" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.[0-7]($|\s).*|[0-1]\.[0-7]\.[0-8]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:258" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">Mozilla (\([0-1]\.[0-7]\)|\([0-1]\.[0-7]\.[0-8]\))</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:263" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">[0-1]\.0($|\s).*|[0-1]\.0\.[0-3]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:262" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^[0-1]\.[0-7]($|\s).*|^[0-1]\.[0-7]\.[0-7]($|\s).*</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2657" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2569" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>x86</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1364" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1197" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.128</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1196" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.2600.1340</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2656" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [2-9]|\d{2,}$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2614" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.00.3700.1000</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Service Pack [4-9]|\d{2,}$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:4" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:47" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2900.2997</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:66" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.2800.1580</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2185" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">6\..*</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:45" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.0.3845.1800</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:8" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.593</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:179" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.0.3790.2794</version>
    </file_state>
    <uname_state id="oval:org.mitre.oval:ste:2941" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <os_release>5.8</os_release>
    </uname_state>
    <patch_state id="oval:org.mitre.oval:ste:2930" version="1" operator="AND" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris">
      <version operation="greater than or equal" datatype="int">38</version>
    </patch_state>
    <file_state id="oval:org.mitre.oval:ste:2929" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <suid operation="equals" datatype="boolean">true</suid>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2928" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix">
      <oexec operation="equals" datatype="boolean">true</oexec>
    </file_state>
    <family_state id="oval:org.mitre.oval:ste:99" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <family>windows</family>
    </family_state>
    <registry_state id="oval:org.mitre.oval:ste:3" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>5.1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2662" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>Service Pack 1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2568" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>ia64</value>
    </registry_state>
  </states>
  <variables>
    <local_variable id="oval:org.mitre.oval:var:248" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\system32\Windows Media\Server</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="The directory for .NET Framework 2.0." datatype="string" id="oval:org.mitre.oval:var:831" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\Microsoft.NET\Framework\v2.0.50727\</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="The shared WMI directory." datatype="string" id="oval:org.mitre.oval:var:443" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\WMI</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:241" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Crystal Decisions\1.1\Managed</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:245" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\system</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:246" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\MSN Messenger</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:247" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1071"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:363" datatype="string" comment="Microsft shared Visual Basic directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\Microsoft Shared\VBA\VBA6</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="The path to mspub.exe" datatype="string" id="oval:org.mitre.oval:var:297" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:2163"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:205" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>InetPub\scripts\proxy</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:249" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\System\Ole DB folder</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:250" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1478"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:252" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1509"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:208" version="2" datatype="string" comment="Microsoft ISA Server directory">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:39"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:253" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1525"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:998" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\Microsoft.NET\Framework\v2.0.50727</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:254" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\web server extensions\50\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:255" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\web server extensions\40\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:204" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\Microsoft.NET\Framework</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:256" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\web server extensions\40\isapi</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:216" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:403"/>
        <literal_component>Reader\plug_ins</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:217" comment="..." version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:417"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:218" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\TextConv</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:202" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\SysWOW64</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:257" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1558"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:220" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
    </local_variable>
    <local_variable comment="..." id="oval:org.mitre.oval:var:214" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\OFFICE11</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="Office 2000 installation directory" id="oval:org.mitre.oval:var:728" version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:120"/>
    </local_variable>
    <local_variable comment="Install directory of  MSO.DLL" id="oval:org.mitre.oval:var:219" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\OFFICE10</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:207" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\syswow64</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:222" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\Microsoft Shared\CDO</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:112" comment="Windows system 32 drivers directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1967"/>
        <literal_component>\system32\drivers</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:227" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:574"/>
        <literal_component>\web server extensions\50\isapi\_vti_adm</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:228" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:577"/>
        <literal_component>WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2180_x-ww_522f9f82</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="The shared GRPHFLT directory." datatype="string" id="oval:org.mitre.oval:var:619" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\GRPHFLT</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:26" comment="Windows system 32 directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1967"/>
        <literal_component>\System32</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:229" comment="Windows Media Player in the Program Files Directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Windows Media Player</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:224" comment="Macromedia Flash subdirectory of Windows system 32 directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\system32\Macromed\Flash</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:223" comment="..." version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:524"/>
    </local_variable>
    <local_variable comment="..." id="oval:org.mitre.oval:var:230" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:660"/>
        <literal_component>OFFICE11</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:232" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\System\MAPI\1033\NT</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:233" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\System\MSMAPI\1033</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:234" comment="..." version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:719"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:235" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:329"/>
        <literal_component>\RES</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="Windows system 32 directory" datatype="string" id="oval:org.mitre.oval:var:203" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\system32\inetsrv</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:215" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Windows NT\Accessories</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:237" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\Help\SBSI\Training</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:212" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\System\msadc</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="Microsoft Agent directory" id="oval:org.mitre.oval:var:759" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\msagent</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="..." id="oval:org.mitre.oval:var:221" version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:493"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:226" comment="..." version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:562"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:238" comment="..." version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:796"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:213" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\system32\Drivers</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:239" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\Microsoft Shared\TextConv</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:240" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\System\MAPI\1033</literal_component>
      </concat>
    </local_variable>
    <local_variable comment="..." id="oval:org.mitre.oval:var:231" version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:663"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:251" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1486"/>
    </local_variable>
    <local_variable comment="Windows system 32 drivers directory" datatype="string" id="oval:org.mitre.oval:var:242" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\SYSTEM32\DRIVERS</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:206" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\microsoft shared\triedit</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:236" comment="..." version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Exchsrvr\res</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:225" comment="..." version="1" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:554"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:244" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:243" datatype="string" comment="Windows system 32 directory" version="1">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:842"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:210" datatype="string" comment="Windows system 32 directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:329"/>
        <literal_component>\bin</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:211" comment="Windows system 32 directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\System32</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:201" comment="Windows system 32 drivers directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\system32\drivers</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:200" comment="Windows system 32 directory" version="1" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\System32</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:209" datatype="string" comment="Base path to vgx.dll, part of Vector Markup Language (VML) implementation." version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Common Files\Microsoft Shared\VGX</literal_component>
      </concat>
    </local_variable>
  </variables>
</oval_definitions>