<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:win-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:ind-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent" xmlns:hpux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux" xmlns:sol-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:linux-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5">
  <generator>
    <oval:product_name>The MITRE Corporation</oval:product_name>
    <oval:schema_version>5.2</oval:schema_version>
    <oval:timestamp>2007-03-22T10:20:50.162-04:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:842" version="1" class="vulnerability">
      <metadata>
        <title>MS Windows Media Service Denial of Service</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <product>Windows Media Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0905" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0905"/>
        <description>Unknown vulnerability in Windows Media Station Service and Windows Media Monitor Service components of Windows Media Services 4.1 allows remote attackers to cause a denial of service (disallowing new connections) via a certain sequence of TCP/IP packets.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2006-10-31T04:13:00.000-04:00" comment="Replaced reference to obj:1374 with reference to obj:1550 since it referencess Product\Options and not ProductOptions in the controlset registry key.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-11-21T04:13:00.000-04:00">INTERIM</status_change>
            <modified comment="Fixed obj:1078: Removed HKEY_LOCAL_MACHINE\ from the key, as it's specified as the hive.  Implemented by Harvey Rubinovitz." date="2007-01-22T00:34:00.741-05:00">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="AND" comment="Windows Media Services 4.1 is installed on Microsoft Windows 2000 Server">
            <criterion comment="Windows Media Services 4.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1602"/>
            <criteria operator="AND" comment="Windows 2000 Server is installed">
              <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
              <criteria operator="OR" comment="Windows NT server product option">
                <criterion comment="this is an NT Server (stand-alone)" negate="false" test_ref="oval:org.mitre.oval:tst:2408"/>
                <criterion comment="this is an NT Server (domain controller)" negate="false" test_ref="oval:org.mitre.oval:tst:3035"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="the version of nscm.exe is less than 4.1.0.3934" negate="false" test_ref="oval:org.mitre.oval:tst:1601"/>
          <criterion comment="the version of nspmon.exe is less than 4.1.0.3934" negate="false" test_ref="oval:org.mitre.oval:tst:1600"/>
          <criterion comment="the patch kb832359 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1599"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="configured to only offer streaming media over unicast" negate="true" test_ref="oval:org.mitre.oval:tst:1598"/>
          <criterion comment="the Windows Media Station service is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1597"/>
          <criterion comment="the Windows Media Monitor service is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:1596"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:812" version="3" class="vulnerability">
      <metadata>
        <title>Outlook Express 6 (S03-Gold) WAB Remote Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Outlook Express</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-0014" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0014"/>
        <description>Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-12T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-30T04:13:00.000-04:00" comment="Replaced periods with commas used to check Outlook Version in ste:1485.  Modified by Harvey Rubinovitz">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <modified date="2006-10-30T12:13:00.000-04:00" comment="Added beginning anchor to ste:1485 to eliminate potential mid-string matches.  Modified by Matthew Wojcik.">
              <contributor organization="BigFix, Inc">Anna Min</contributor>
            </modified>
            <status_change date="2006-10-30T12:13:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-11-14T08:58:00.007-05:00">ACCEPTED</status_change>
            <modified comment="Removed unneeded ste:2282 from tst:2437. Deprecated ste:2282 since it is no longer used." date="2007-01-12T07:06:00.595-05:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-01-12T07:08:54.564-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:00.679-05:00">ACCEPTED</status_change>
            <modified comment="Changed affected platform to Microsoft Windows Server 2003. Implemented by Jon Baker of the MITRE Corporation." date="2007-03-14T20:54:00.610-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-14T20:56:21.701-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
        <criterion comment="Win2K/XP/2003 is patched" negate="true" test_ref="oval:org.mitre.oval:tst:2437"/>
        <criterion comment="64-Bit version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
        <criterion comment="Outlook Express 6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1633"/>
        <criterion comment="the version of inetcomm.dll is less than 6.0.3790.2663" negate="false" test_ref="oval:org.mitre.oval:tst:1632"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:772" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Usermod Local Unauthorized Access Vulnerability instead of usermod Recursive Ownership Error.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.650-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:42:53.692-04:00">INTERIM</status_change>
            <modified comment="Updated definition title. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:42:00.035-04:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:762" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 5)</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft SharePoint Team Services</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:53:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows 2000, XP, or 2003 is installed">
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
            <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="SharePoint Team Services are enabled (2K, XP, 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2379"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:748" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsServer2003-x64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsServer2003-x64-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsServer2003-x64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:26.559-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:720" comment="Microsoft Windows XP Professional x64 Edition SP1 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:746" class="vulnerability" version="1">
      <metadata>
        <title>Word Malformed Data Structures Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6456" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456"/>
        <description>Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5994.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:26.417-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:238" comment="Word Malformed String Vulnerability"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:718" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsServer2003-x64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsServer2003-x64-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsServer2003-x64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.794-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:730" comment="Microsoft Windows Server 2003 (x64) is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:700" class="vulnerability" version="1">
      <metadata>
        <title>Word Macro Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0208" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0208"/>
        <description>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.484-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8958" test_ref="oval:org.mitre.oval:tst:3510"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6826.0" test_ref="oval:org.mitre.oval:tst:3265"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8125.0" test_ref="oval:org.mitre.oval:tst:3593"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:684" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB929969-WindowsXP-x86-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsXP-x86-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsXP-x86-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.132-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:754" comment="Microsoft Windows XP (x86) SP2 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:679" version="0" class="patch">
      <metadata>
        <title>IE7-KB929969-WindowsServer2003-ia64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsServer2003-ia64-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsServer2003-ia64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:23.989-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition definition_ref="oval:org.mitre.oval:def:396" comment="Microsoft Windows Server 2003 (ia64) Gold is installed"/>
          <extend_definition definition_ref="oval:org.mitre.oval:def:1205" comment="Microsoft Windows Server 2003 (ia64) SP1 is installed"/>
        </criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:675" version="1" class="vulnerability">
      <metadata>
        <title>MS Excel 97 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-14 - wft-14 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2434) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 97 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2435"/>
        <criterion comment="the version of excel.exe is less than 8.00.01.9904" negate="false" test_ref="oval:org.mitre.oval:tst:2434"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:625" version="1" class="vulnerability">
      <metadata>
        <title>MS FrontPage Server Extensions SmartHTML Denial of Service (Test 4)</title>
        <affected family="windows">
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft FrontPage Server Extensions 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0824" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0824"/>
        <description>Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-12-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <modified date="2004-01-14T12:00:00.000-04:00" comment="Changed the definition to look at the file shtml.dll instead of fp5awel.dll.  It was determined that this is where the vulnerability (a buffer overflow) actually existed.  Also added the configuration test saying you are vulnerable if the SmartHTML interpreter is enabled.">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2004-09-14T09:52:00.000-04:00" comment="XP SP2 added">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2004-09-15T12:00:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criteria operator="OR" comment="Windows NT, 2000, or XP is installed">
            <criterion comment="Windows NT 4.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3089"/>
            <criterion comment="Windows 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3085"/>
            <criterion comment="Windows XP is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2838"/>
          </criteria>
          <criterion comment="a vulnerable version of shtml.dll exists (FPSE 2002 or SPTS 2003)" negate="false" test_ref="oval:org.mitre.oval:tst:2490"/>
          <criterion comment="Win2K/XP/2003 service pack 2 (or later) is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2837"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="FrontPage Server Extensions 2002 are enabled (NT, 2K, XP)" negate="false" test_ref="oval:org.mitre.oval:tst:2677"/>
          <criterion comment="SmartHTML interpreter is enabled" negate="false" test_ref="oval:org.mitre.oval:tst:2705"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:586" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 98 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 98</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-16T04:13:00.000-04:00" comment="Modified test 2528 to use obj:492 rather than obj:1443 since they were the same and this definition was the only reference to obj:1443.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2006-10-16T04:13:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 98 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2529"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9716" negate="false" test_ref="oval:org.mitre.oval:tst:2528"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:585" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 97 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-17 - wft-17 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T12:01:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-20T12:00:00.000-04:00" comment="Corrected unknown test">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 97 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2531"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9315" negate="false" test_ref="oval:org.mitre.oval:tst:2530"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:568" class="vulnerability" version="1">
      <metadata>
        <title>PowerPoint Malformed Record Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3877"/>
        <description>Unspecified vulnerability in PowerPoint in Microsoft Office 2000, Office 2002, Office 2003, Office 2004 for Mac, and Office v.X for Mac allows user-assisted attackers to execute arbitrary code via an unspecified "crafted file," a different vulnerability than CVE-2006-3435, CVE-2006-4694, and CVE-2006-3876.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:21.217-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8960" test_ref="oval:org.mitre.oval:tst:3924"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6825.0" test_ref="oval:org.mitre.oval:tst:3484"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8122.0" test_ref="oval:org.mitre.oval:tst:4091"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:540" class="vulnerability" version="1">
      <metadata>
        <title>OLE Dialog Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Interactive Training</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0026" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0026"/>
        <description>The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:21.048-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Oledlg.dll is less than 5.0.2195.7114" test_ref="oval:org.mitre.oval:tst:3179"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Oledlg.dll is less than 5.1.2600.3016" test_ref="oval:org.mitre.oval:tst:3286"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Oledlg.dll is less than 5.2.3790.2813" test_ref="oval:org.mitre.oval:tst:3711"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Oledlg.dll is less than 5.2.3790.601" test_ref="oval:org.mitre.oval:tst:3967"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Oledlg.dll is less than 5.2.3790.2813" test_ref="oval:org.mitre.oval:tst:3711"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:528" class="vulnerability" version="1">
      <metadata>
        <title>Word Malformed Function Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0515" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0515"/>
        <description>Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:20.324-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Word 2000" operator="AND">
        <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8958" test_ref="oval:org.mitre.oval:tst:3510"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:477" version="1" class="vulnerability">
      <metadata>
        <title>MS Exchange / OWA NTLM Authentication Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Exchange Server</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0904" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0904"/>
        <description>Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-20T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1480 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria comment="Software section" operator="AND">
          <criterion comment="Exchange Server 2003 (gold edition) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2760"/>
          <criterion comment="the version of exprox.dll is less than 6.5.6980.57" negate="false" test_ref="oval:org.mitre.oval:tst:2605"/>
          <criterion comment="the patch KB832759 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2604"/>
        </criteria>
        <criteria comment="Configuration section" operator="AND">
          <criterion comment="this is a front-end server providing Outlook Web Access" negate="false" test_ref="oval:org.mitre.oval:tst:2603"/>
          <criterion comment="the back-end server is Exchange Server 2003 running on Windows 2003" negate="false" test_ref="oval:org.mitre.oval:tst:2602"/>
          <criterion comment="HTTP connection reuse is disabled" negate="true" test_ref="oval:org.mitre.oval:tst:2601"/>
          <criterion comment="Kerberos is disabled on the virtual server that hosts OWA on the Exchange Server 2003 back-end server" negate="false" test_ref="oval:org.mitre.oval:tst:2600"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:396" version="0" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (ia64) Gold is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://microsoft:windows:2003::sp1"/>
        <description>A version of Microsoft Windows Server 2003 (ia64) Gold is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:18.086-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="the installed operating system is part of the Microsoft Windows family"/>
        <criterion test_ref="oval:org.mitre.oval:tst:4" comment="a version of Microsoft Windows Server 2003 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:2747" comment="a version of Windows for the ia64 architecture is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:2845" negate="true" comment="a Windows 2000/XP/2003 Service Pack is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:347" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsServer2003-x86-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsServer2003-x86-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsServer2003-x86-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:16.987-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:565" comment="Microsoft Windows Server 2003 (x86) SP1 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:332" class="vulnerability" version="1">
      <metadata>
        <title>Word Count Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-6561" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6561"/>
        <description>Unspecified vulnerability in Microsoft Word 2000, 2002, and Word Viewer 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted DOC file that triggers memory corruption, as demonstrated via the 12122006-djtest.doc file, a different issue than CVE-2006-5994 and CVE-2006-6456.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:16.847-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:238" comment="Word Malformed String Vulnerability"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:324" version="1">
      <metadata>
        <title>Microsoft Visual Studio .NET 2005 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft Visual Studio .NET 2005 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:16.700-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visual Studio .NET 2005 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:149"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:301" class="vulnerability" version="1">
      <metadata>
        <title>Excel Malformed Record Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Office</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0671"/>
        <description>Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:15.385-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Office 2000" operator="AND">
          <criterion comment="The Office 2000 (or later) version of Mso9.dll is installed." test_ref="oval:org.mitre.oval:tst:194"/>
          <criterion comment="the version of Mso9.dll is less than 9.0.0.8960" test_ref="oval:org.mitre.oval:tst:3924"/>
        </criteria>
        <criteria comment="Office 2002" operator="AND">
          <criterion comment="The Office 2002 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:139"/>
          <criterion comment="the version of Mso.dll is less than 10.0.6825.0" test_ref="oval:org.mitre.oval:tst:3484"/>
        </criteria>
        <criteria comment="Office 2003" operator="AND">
          <criterion comment="The Office 2003 (or later) version of Mso.dll is installed." test_ref="oval:org.mitre.oval:tst:69"/>
          <criterion comment="the version of Mso.dll is less than 11.0.8122.0" test_ref="oval:org.mitre.oval:tst:4091"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:289" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB929969-WindowsServer2003-x86-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsServer2003-x86-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsServer2003-x86-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:14.690-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition definition_ref="oval:org.mitre.oval:def:165" comment="Microsoft Windows Server 2003 (x86) Gold is installed"/>
          <extend_definition definition_ref="oval:org.mitre.oval:def:565" comment="Microsoft Windows Server 2003 (x86) SP1 is installed"/>
        </criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:720" version="0" class="inventory">
      <metadata>
        <title>Microsoft Windows XP Professional x64 Edition SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://microsoft:windows:xp::sp1"/>
        <description>A version of Microsoft Windows XP Professional x64 Edition Service Pack 1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:24.909-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="the installed operating system is part of the Microsoft Windows family"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3" comment="a version of Microsoft Windows XP is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3653" comment="a version of Windows for the x64 architecture is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:2843" comment="Win2K/XP/2003 service pack 1 is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:286" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB929969-WindowsServer2003-x64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsServer2003-x64-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsServer2003-x64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:14.535-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:720" comment="Microsoft Windows XP Professional x64 Edition SP1 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:754" version="0" class="inventory">
      <metadata>
        <title>Microsoft Windows XP (x86) SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://microsoft:windows:xp::sp2"/>
        <description>A version of Microsoft Windows XP (x86) Service Pack 2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:26.869-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="the installed operating system is part of the Microsoft Windows family"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3" comment="a version of Microsoft Windows XP is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3823" comment="a version of Windows for the x86 architecture is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3019" comment="Win2K/XP/2003 service pack 2 is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:283" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsXP-x86-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsXP-x86-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsXP-x86-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:14.388-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:754" comment="Microsoft Windows XP (x86) SP2 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:282" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB928090-WindowsServer2003-ia64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB928090-WindowsServer2003-ia64-enu.exe"/>
        <description>The patch IE7-KB928090-WindowsServer2003-ia64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-016 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:14.196-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:1205" comment="Microsoft Windows Server 2003 (ia64) SP1 is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criteria operator="OR">
          <criterion test_ref="oval:org.mitre.oval:tst:3721" comment="the version of Iexplore.exe is less than 7.0.6000.16414"/>
          <criterion test_ref="oval:org.mitre.oval:tst:3876" comment="the version of Mshtml.dll is less than 7.0.6000.16414"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:257" class="vulnerability" version="1">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0219" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0219"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2006-4697.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:13.595-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:1120" comment="COM Object Instantiation Memory Corruption Vulnerability"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:238" class="vulnerability" version="1">
      <metadata>
        <title>Word Malformed String Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5994" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5994"/>
        <description>Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that triggers memory corruption, a different vulnerability than CVE-2006-6456.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:12.909-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8958" test_ref="oval:org.mitre.oval:tst:3510"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6826.0" test_ref="oval:org.mitre.oval:tst:3265"/>
        </criteria>
        <criteria comment="Word 2003" operator="AND">
          <extend_definition comment="Microsoft Word 2003 is installed" definition_ref="oval:org.mitre.oval:def:475"/>
          <criterion comment="the version of winword.exe is less than 11.0.8125.0" test_ref="oval:org.mitre.oval:tst:3593"/>
        </criteria>
        <criteria comment="Word Viewer" operator="AND">
          <extend_definition comment="Microsoft Word Viewer is installed" definition_ref="oval:org.mitre.oval:def:737"/>
          <criterion comment="the version of wordview.exe is less than 11.0.8125.0" test_ref="oval:org.mitre.oval:tst:4101"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:228" version="1" class="inventory">
      <metadata>
        <title>Microsoft Windows Vista is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <description>The operating system installed on the system is Microsoft Windows Vista</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-13T12:46:06">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2007-02-13T14:53:06-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:12.775-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="The operating system installed on the system is part of Microsoft Windows family."/>
        <criterion test_ref="oval:org.mitre.oval:tst:192" comment="Microsoft Windows Vista is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:224" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Shell Could Allow Elevation of Privilege</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0211" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0211"/>
        <description>The hardware detection functionality in the Windows Shell in Microsoft Windows XP SP2 and Professional, and Server 2003 SP1 allows local users to gain privileges via an unvalidated parameter to a function related to the "detection and registration of new hardware."</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-13T14:38:21">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-02-20T13:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Fixed typo in criteria block for S03,SP1 (it was using the S03,Gold test)." date="2007-03-02T12:02:00.248-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:12.613-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Microsoft Windows XP Service Pack 2" operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of shell32.dll is less than 6.0.2900.3051" test_ref="oval:org.mitre.oval:tst:3365"/>
        </criteria>
        <criteria comment="Microsoft Windows XP (64-bit)" operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.2867" test_ref="oval:org.mitre.oval:tst:3512"/>
        </criteria>
        <criteria comment="Microsoft Windows Server 2003 (Gold)" operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.630" test_ref="oval:org.mitre.oval:tst:3882"/>
        </criteria>
        <criteria comment="Microsoft Windows Server 2003 Service Pack 1" operator="AND">
          <extend_definition definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of shell32.dll is less than 6.0.3790.2867" test_ref="oval:org.mitre.oval:tst:3512"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:214" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability in Microsoft Data Access Components Could Allow Remote Code Execution</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5559" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5559"/>
        <description>The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-13T14:38:21">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-02-20T13:20:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected XP and S03 tests to look for versions of Msado15.dll instead of Msadco.dll." date="2007-03-02T12:18:00.315-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-21T16:17:11.974-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Windows 2000 SP4 with MDAC 2.5 SP3" operator="AND">
          <extend_definition comment="Windows 2000 SP4" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="MDAC 2.5 (SP3) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:729"/>
          <criterion comment="the version of msadco.dll is less than 2.53.6307.0" test_ref="oval:org.mitre.oval:tst:4137"/>
        </criteria>
        <criteria comment="Windows 2000 SP4 with MDAC 2.7 SP1" operator="AND">
          <extend_definition comment="Windows 2000 SP4" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="MDAC 2.7 (SP1) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2382"/>
          <criterion comment="the version of msadco.dll is less than 2.71.9054.0" test_ref="oval:org.mitre.oval:tst:4020"/>
        </criteria>
        <criteria comment="Windows 2000 SP4 with MDAC 2.8" operator="AND">
          <extend_definition comment="Windows 2000 SP4" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="MDAC 2.8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
          <criterion comment="the version of msadco.dll is less than 2.80.1064.0" test_ref="oval:org.mitre.oval:tst:3591"/>
        </criteria>
        <criteria comment="Windows 2000 SP4 with MDAC 2.8 SP1" operator="AND">
          <extend_definition comment="Windows 2000 SP4" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="MDAC 2.8 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
          <criterion comment="the version of msadco.dll is less than 2.81.1128.0" test_ref="oval:org.mitre.oval:tst:3619"/>
        </criteria>
        <criteria comment="Windows XP SP2 with MDAC 2.8 SP1" operator="AND">
          <extend_definition comment="Windows XP SP2" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="MDAC 2.8 SP1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
          <criterion comment="the version of msado15.dll is less than 2.81.1128.0" test_ref="oval:org.mitre.oval:tst:3821"/>
        </criteria>
        <criteria comment="Windows Server 2003 with MDAC 2.8" operator="AND">
          <extend_definition comment="Windows Server 2003" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="MDAC 2.8 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2363"/>
          <criterion comment="the version of msado15.dll is less than 2.80.1064.0" test_ref="oval:org.mitre.oval:tst:3787"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:187" class="vulnerability" version="1">
      <metadata>
        <title>Word Malformed Drawing Object Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0209" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0209"/>
        <description>Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a Word file with a malformed drawing object, which leads to memory corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:06.934-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Word 2000" operator="AND">
          <extend_definition comment="Microsoft Word 2000 is installed" definition_ref="oval:org.mitre.oval:def:455"/>
          <criterion comment="the version of winword.exe is less than 9.0.0.8958" test_ref="oval:org.mitre.oval:tst:3510"/>
        </criteria>
        <criteria comment="Word 2002" operator="AND">
          <extend_definition comment="Microsoft Word 2002 is installed" definition_ref="oval:org.mitre.oval:def:973"/>
          <criterion comment="the version of winword.exe is less than 10.0.6826.0" test_ref="oval:org.mitre.oval:tst:3265"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:186" version="1" class="vulnerability">
      <metadata>
        <title>Vulnerability in Windows Image Acquisition Service Could Allow Elevation of Privilege</title>
        <affected family="windows">
          <platform>Microsoft Windows XP</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0210" ref_url="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0210"/>
        <description>The Window Image Acquisition (WIA) Service in Microsoft Windows XP SP2 allows local users to gain privileges via unspecified vectors involving an "unchecked buffer," probably a buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-13T14:38:21">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2007-02-20T13:20:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:06.807-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Microsoft Windows XP Service Pack 2" operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:521"/>
        <criterion comment="the version of Wiaservc.dll is less than 5.1.2600.3051" test_ref="oval:org.mitre.oval:tst:3227"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1754" version="1" class="vulnerability">
      <metadata>
        <title>HP Security Update Fixes VirtualVault Apache HTTP Request Smuggling Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>LDAP</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1689" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1689"/>
        <description>Unspecified vulnerability in su in HP HP-UX B.11.11, when using the LDAP netgroup feature, allows local users to gain unspecified access.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-04-06T06:39:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-12T05:16:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T21:15:00.392-04:00">
              <contributor organization="Opsware, Inc">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-03-19T21:23:35.434-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="Patch PHCO_34545 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:737"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1690" version="1" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1509"/>
        <description>/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.585-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:28:59.623-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX2-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:771"/>
        <criterion comment="Patch PHCO_32149 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:770"/>
        <criterion comment="Patch PHCO_32926 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:769"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1660" version="1" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1509"/>
        <description>/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.577-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:27:53.606-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
          <criteria operator="AND" comment="700 Series OS Release 11.11">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:961"/>
        <criterion comment="Patch PHCO_33214 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:788"/>
        <criterion comment="Patch PHCO_33215 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:787"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:162" class="vulnerability" version="1">
      <metadata>
        <title>Interactive Training Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Interactive Training</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-3448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3448"/>
        <description>Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a long Syllabus string in crafted bookmark link files (cbo, cbl, or .cbm), a different issue than CVE-2005-1212.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:57.406-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
        </criteria>
        <criterion comment="the version of Orun32.exe is less than 3.5.0.118" test_ref="oval:org.mitre.oval:tst:3436"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:981" version="1">
      <metadata>
        <title>Microsoft Visual Studio .NET 2002,SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft Visual Studio .NET 2002,SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:29.144-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visual Studio .NET 2002 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:334"/>
        <criterion comment="Service Pack 1 for Visual Studio .NET 2002 is installed" test_ref="oval:org.mitre.oval:tst:3317"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:168" version="1">
      <metadata>
        <title>Microsoft Visual Studio .NET 2003,SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft Visual Studio .NET 2003,SP1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:59.273-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visual Studio .NET 2003 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:756"/>
        <criterion comment="Service Pack 1 for Visual Studio .NET 2003 is installed" test_ref="oval:org.mitre.oval:tst:3648"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:166" version="1">
      <metadata>
        <title>Microsoft Visual Studio .NET 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft Visual Studio .NET 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:58.485-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visual Studio .NET 2003 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:756"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:157" class="vulnerability" version="1">
      <metadata>
        <title>MFC Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0025" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0025"/>
        <description>The MFC component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 and Visual Studio .NET 2000, 2002 SP1, 2003, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. NOTE: this might be due to a stack-based buffer overflow in the the AfxOleSetEditMenu function in MFC42u.dll.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:54.679-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="64-Bit (Itanium) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc42u.dll is less than 6.5.9146.0" test_ref="oval:org.mitre.oval:tst:4026"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="64-Bit (Itanium) version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc42u.dll is less than 6.0.9792.0" test_ref="oval:org.mitre.oval:tst:3532"/>
        </criteria>
        <criteria comment="S03 (x86)" operator="AND">
          <criterion comment="Windows Server 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2761"/>
          <criterion comment="64-Bit (Itanium) version of Windows is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc40u.dll is less than 4.1.0.6141" test_ref="oval:org.mitre.oval:tst:3685"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="64-Bit (Itanium) version of Windows is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2747"/>
          <criterion comment="the version of Mfc42u.dll is less than 6.5.9146.0" test_ref="oval:org.mitre.oval:tst:4026"/>
        </criteria>
        <criteria comment="Visual Studio .NET 2002" operator="AND">
          <extend_definition comment="Visual Studio .NET 2002 is installed" definition_ref="oval:org.mitre.oval:def:1131"/>
          <criterion comment="the version of Mfc70.dll is less than 7.0.9801.0" test_ref="oval:org.mitre.oval:tst:3488"/>
        </criteria>
        <criteria comment="Visual Studio .NET 2002 Service Pack 1" operator="AND">
          <extend_definition comment="Visual Studio .NET 2002,SP1 is installed" definition_ref="oval:org.mitre.oval:def:981"/>
          <criterion comment="the version of Mfc70.dll is less than 7.0.9975.0" test_ref="oval:org.mitre.oval:tst:4011"/>
        </criteria>
        <criteria comment="Visual Studio .NET 2003" operator="AND">
          <extend_definition comment="Visual Studio .NET 2003 is installed" definition_ref="oval:org.mitre.oval:def:166"/>
          <criterion comment="the version of Mfc71.dll is less than 7.10.5057.0" test_ref="oval:org.mitre.oval:tst:3844"/>
        </criteria>
        <criteria comment="Visual Studio .NET 2003 Service Pack 1" operator="AND">
          <extend_definition comment="Visual Studio .NET 2003,SP1 is installed" definition_ref="oval:org.mitre.oval:def:168"/>
          <criterion comment="the version of Mfc71.dll is less than 7.10.6041.0" test_ref="oval:org.mitre.oval:tst:3815"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1412" version="1" class="vulnerability">
      <metadata>
        <title>passwd Local DoS Vulnerability (B.11.00)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Operating System</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1509" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1509"/>
        <description>/sbin/passwd in HP-UX B.11.00, B.11.11, and B.11.23 before 20060326 "does not recover gracefully from some error conditions," which allows local users to cause a denial of service.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-29T06:11:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-04-06T06:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-31T09:45:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:25:00.738-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:27:07.769-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
        <criterion comment="OS-Core.UX-CORE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:961"/>
        <criterion comment="Patch PHCO_33219 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:960"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:125" class="vulnerability" version="1">
      <metadata>
        <title>HTML Help ActiveX Control Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0214" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0214"/>
        <description>The HTML Help ActiveX control (Hhctrl.ocx) in Microsoft Windows 2000 SP3, XP SP2 and Professional, 2003 SP1 allows remote attackers to execute arbitrary code via unspecified functions, related to uninitialized parameters.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:46.946-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Win2K,SP4" operator="AND">
          <extend_definition comment="Windows 2000, SP4 is installed" definition_ref="oval:org.mitre.oval:def:229"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.620" test_ref="oval:org.mitre.oval:tst:196"/>
        </criteria>
        <criteria comment="WinXP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
        </criteria>
        <criteria comment="WinXP,SP1 (64-bit)" operator="AND">
          <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
        </criteria>
        <criteria comment="S03-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.620" test_ref="oval:org.mitre.oval:tst:196"/>
        </criteria>
        <criteria comment="S03,SP1" operator="AND">
          <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          <criterion comment="the version of Hhctrl.ocx is less than 5.2.3790.2847" test_ref="oval:org.mitre.oval:tst:3154"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1237" version="1" class="vulnerability">
      <metadata>
        <title>Webproxy HTTP Request Smuggling (B.11.04)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T21:23:00.442-04:00">
              <contributor organization="Opsware, Inc">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-03-19T21:30:48.475-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="VirtualvaultTS A.04.70 is installed without patch PHSS_34169 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1062"/>
          <criterion comment="Patch PHSS_34169 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2341"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.70 is installed without patch PHSS_34121 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.70 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1061"/>
          <criterion comment="Patch PHSS_34121 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1060"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.60 is installed without patch PHSS_34170 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1059"/>
          <criterion comment="Patch PHSS_34170 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1058"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.60 is installed without patch PHSS_34120 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.60 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1057"/>
          <criterion comment="Patch PHSS_34120 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1056"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultTS A.04.50 is installed without patch PHSS_34171 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultTS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1055"/>
          <criterion comment="Patch PHSS_34171 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1054"/>
        </criteria>
        <criteria operator="AND" comment="VirtualvaultWS A.04.50 is installed without patch PHSS_34119 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="VirtualvaultWS A.04.50 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1053"/>
          <criterion comment="Patch PHSS_34119 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1052"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed without patch PHSS_34203 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.10 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1051"/>
          <criterion comment="Patch PHSS_34203 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1050"/>
        </criteria>
        <criteria operator="AND" comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed without patch PHSS_34204 or later">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
            <criteria operator="AND" comment="700 Series OS Release 11.04">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.04">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.04" negate="false" test_ref="oval:org.mitre.oval:tst:1276"/>
            </criteria>
          </criteria>
          <criterion comment="HP_Webproxy.HPWEB-PX-CORE A.02.00 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1049"/>
          <criterion comment="Patch PHSS_34204 or subsequent is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1048"/>
        </criteria>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:1211" version="2">
      <metadata>
        <title>Microsoft Office 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Office 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:///microsoft:office:12"/>
        <description>The application Microsoft Office 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:15:44.461-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-03-05T09:15:44.461-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:45.739-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office 2007 is installed" test_ref="oval:org.mitre.oval:tst:3839"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1205" version="0" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (ia64) SP1 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://microsoft:windows:2003::sp1"/>
        <description>A version of Microsoft Windows Server 2003 (ia64) Service Pack 1 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:45.596-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="the installed operating system is part of the Microsoft Windows family"/>
        <criterion test_ref="oval:org.mitre.oval:tst:4" comment="a version of Microsoft Windows Server 2003 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:2747" comment="a version of Windows for the ia64 architecture is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:2843" comment="Win2K/XP/2003 service pack 1 is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:730" version="0" class="inventory">
      <metadata>
        <title>Microsoft Windows Server 2003 (x64) is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe://microsoft:windows:2003::sp1"/>
        <description>A version of Microsoft Windows Server 2003 (x64) is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:17:25.745-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion test_ref="oval:org.mitre.oval:tst:99" comment="the installed operating system is part of the Microsoft Windows family"/>
        <criterion test_ref="oval:org.mitre.oval:tst:4" comment="a version of Microsoft Windows Server 2003 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3653" comment="a version of Windows for the x64 architecture is installed"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1162" version="0" class="patch">
      <metadata>
        <title>patch IE7-KB929969-WindowsServer2003-x64-enu.exe should be installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer 7</product>
        </affected>
        <reference source="VENDOR" ref_id="IE7-KB929969-WindowsServer2003-x64-enu.exe"/>
        <description>The patch IE7-KB929969-WindowsServer2003-x64-enu.exe that addresses the vulnerabilities discussed in Microsoft Security Bulletin MS07-004 should be installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:00:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2007-03-05T09:00:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:43.545-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition definition_ref="oval:org.mitre.oval:def:730" comment="Microsoft Windows Server 2003 (x64) is installed"/>
        <extend_definition definition_ref="oval:org.mitre.oval:def:627" comment="Internet Explorer 7 is installed"/>
        <criterion test_ref="oval:org.mitre.oval:tst:3946" comment="the version of Vgx.dll is less than 7.0.6000.16386"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1141" class="vulnerability" version="1">
      <metadata>
        <title>FTP Server Response Parsing Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0217"/>
        <description>The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <modified comment="Corrected affected platform name to Microsoft Windows Server 2003. Implemented by Jon Baker of The MITRE Corporation." date="2007-02-20T19:29:00.895-05:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:42.873-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <extend_definition definition_ref="oval:org.mitre.oval:def:1120" comment="COM Object Instantiation Memory Corruption Vulnerability"/>
      </criteria>
    </definition>
    <definition class="inventory" id="oval:org.mitre.oval:def:1131" version="1">
      <metadata>
        <title>Microsoft Visual Studio .NET 2002 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <description>Microsoft Visual Studio .NET 2002 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:42.605-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Visual Studio .NET 2002 Installed" negate="false" test_ref="oval:org.mitre.oval:tst:334"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1120" class="vulnerability" version="1">
      <metadata>
        <title>COM Object Instantiation Memory Corruption Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Internet Explorer</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-4697" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4697"/>
        <description>Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-02-14T09:49:32">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2007-02-16T21:55:00.000-04:00">DRAFT</status_change>
            <modified comment="Fixed typo in ste:146, used for file version check for mshtml.dll for Server 2003.  Implemented by Matthew Wojcik." date="2007-03-05T11:43:00.839-05:00">
              <contributor organization="GFI Software">Daniel Tarnu</contributor>
            </modified>
            <status_change date="2007-03-21T16:16:42.248-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria comment="Server 2003-Gold (IE7)" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" negate="false" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE7)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" negate="false" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="IE 7 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
          <extend_definition comment="Internet Explorer 7 is installed" definition_ref="oval:org.mitre.oval:def:627"/>
          <criterion comment="the version of mshtml.dll is less than 7.0.6000.16414" negate="false" test_ref="oval:org.mitre.oval:tst:3906"/>
        </criteria>
        <criteria comment="Server 2003-Gold" operator="AND">
          <extend_definition comment="Windows Server 2003 (Gold) is installed (IE6)" definition_ref="oval:org.mitre.oval:def:165"/>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.630" negate="false" test_ref="oval:org.mitre.oval:tst:3764"/>
        </criteria>
        <criteria comment="XP,SP1 (64-bit) and Server 2003, SP1 (IE6)" operator="AND">
          <criteria operator="OR" comment="Windows XP (64-bit,SP1) or Server 2003 (SP1) is installed">
            <extend_definition comment="Windows XP, SP1 (64-bit) is installed" definition_ref="oval:org.mitre.oval:def:480"/>
            <extend_definition comment="Windows Server 2003, SP1 is installed" definition_ref="oval:org.mitre.oval:def:565"/>
          </criteria>
          <extend_definition comment="Internet Explorer 6 is installed" definition_ref="oval:org.mitre.oval:def:563"/>
          <criterion comment="the version of mshtml.dll is less than 6.0.3790.2858" negate="false" test_ref="oval:org.mitre.oval:tst:3187"/>
        </criteria>
        <criteria comment="IE 6 on Windows XP,SP2" operator="AND">
          <extend_definition comment="Windows XP, SP2 is installed" definition_ref="oval:org.mitre.oval:def:521"/>
      