<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#hpux hpux-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.9</oval:schema_version>
    <oval:timestamp>2012-01-27T05:09:29.990-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:992" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX Running on Itanium Platforms Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3295" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3295"/>
        <description>Unspecified vulnerability in HP-UX B.11.23 on Itanium platforms allows local users to cause a denial of service due to a "specific stack size."</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-11T12:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-12T09:18:00.000-04:00">DRAFT</status_change>
            <modified date="2006-01-31T12:19:00.000-04:00" comment="Updated reference to CVE-2005-3295.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:54.943-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.727-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.989-04:00">ACCEPTED</status_change>
            <modified comment="Updated for CVE-2005-3295" date="2008-09-09T10:39:00.374-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-09-09T10:42:43.389-04:00">INTERIM</status_change>
            <status_change date="2008-09-29T04:00:53.978-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX01233">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:1350"/>
        <criteria negate="true" operator="OR" comment="Patch PHKL_33713 and PHKL_33714 are installed">
          <criterion comment="Patch PHKL_33713 is installed" test_ref="oval:org.mitre.oval:tst:1349"/>
          <criterion comment="Patch PHKL_33714 is installed" test_ref="oval:org.mitre.oval:tst:1348"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:935" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX PMTUD Remote DoS (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-1192" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1192"/>
        <description>Unknown vulnerability in HP-UX B.11.00, B.11.04, B.11.11, B.11.22, and B.11.23, when running TCP/IP on IPv4, allows remote attackers to cause a denial of service via certain packets, related to the PMTU, a different vulnerability than CVE-2004-1060.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-02-01T11:45:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-09T12:19:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:30:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.649-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.897-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:935 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:25.156-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:49.198-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:1442"/>
        <criterion negate="true" comment="Patch PHNE_32606 is installed" test_ref="oval:org.mitre.oval:tst:1441"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:899" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX 11.04 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:54.417-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:16:01.065-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:23:00.955-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:23:41.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:28.351-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.562-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.792-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:899 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:58.073-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:48.788-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.04">
          <criteria operator="AND" comment="700 Series OS Release 11.04">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.04">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_33427 is installed" test_ref="oval:org.mitre.oval:tst:3468"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8717" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0217" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217"/>
        <description>The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:17.264-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:51.843-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:34.551-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8622" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3868" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3868"/>
        <description>Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:08.423-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:46.751-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:30.452-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8608" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3876" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3876"/>
        <description>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:13.780-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:43.979-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:28.530-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8603" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3874" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3874"/>
        <description>Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:12.227-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:42.619-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:27.102-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8566" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3869" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3869"/>
        <description>Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:09.178-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:40.132-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:24.692-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8558" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2673" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2673"/>
        <description>The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to bypass intended access restrictions and connect to arbitrary sites via unspecified vectors, related to a declaration that lacks the final keyword.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:21.171-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:37.867-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:22.941-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8535" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running OpenSSL, Remote Unauthorized Data Injection, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:03.859-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:34.867-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:19.723-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02482">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20966"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21305"/>
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20418"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21054"/>
            <criterion comment="openssl.OPENSSL-DOC version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20471"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21309"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:20594"/>
            <criterion comment="openssl.OPENSSL-MAN version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21258"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21380"/>
            <criterion comment="openssl.OPENSSL-SRC version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21406"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.002" test_ref="oval:org.mitre.oval:tst:21371"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02482">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21401"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21226"/>
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20912"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20516"/>
            <criterion comment="openssl.OPENSSL-DOC version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21017"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20853"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21188"/>
            <criterion comment="openssl.OPENSSL-MAN version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20482"/>
            <criterion comment="openssl.OPENSSL-SRC version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21318"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:20462"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.001" test_ref="oval:org.mitre.oval:tst:21439"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02482">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21348"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21238"/>
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:20944"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:20917"/>
            <criterion comment="openssl.OPENSSL-DOC version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21411"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:20833"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21259"/>
            <criterion comment="openssl.OPENSSL-MAN version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21140"/>
            <criterion comment="openssl.OPENSSL-SRC version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21462"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21184"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08l.003" test_ref="oval:org.mitre.oval:tst:21348"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8520" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2625" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625"/>
        <description>XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:18.123-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:33.262-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:17.719-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8512" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running sendmail, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2261"/>
        <description>Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:01:59.793-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:32.422-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:17.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21292"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:20788"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40388 is installed" test_ref="oval:org.mitre.oval:tst:20863"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21292"/>
          <criterion negate="true" comment="Patch PHNE_40393 is installed" test_ref="oval:org.mitre.oval:tst:21246"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8475" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3872" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3872"/>
        <description>Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:10.687-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:29.478-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:14.737-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8453" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2676" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2676"/>
        <description>Unspecified vulnerability in JNLPAppletlauncher in Sun Java SE, and SE for Business, in JDK and JRE 6 Update 14 and earlier and JDK and JRE 5.0 Update 19 and earlier; and Java SE for Business in SDK and JRE 1.4.2_21 and earlier; allows remote attackers to create or modify arbitrary files via vectors involving an untrusted Java applet that accesses an old version of JNLPAppletLauncher.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:23.448-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:27.161-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:12.965-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8415" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2675" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2675"/>
        <description>Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:22.665-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:23.644-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:09.779-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:840" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Request Smuggling</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2088" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2088"/>
        <description>The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8396" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3873" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873"/>
        <description>The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:11.474-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:21.820-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:07.739-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8366" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Unauthorized Data Injection, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3555" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555"/>
        <description>The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a "plaintext injection" attack, aka the "Project Mogul" issue.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:01.435-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:20.568-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:06.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02498">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21301"/>
          <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21187"/>
          <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21265"/>
          <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21212"/>
          <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20981"/>
          <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20369"/>
          <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21323"/>
          <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21018"/>
          <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21151"/>
          <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21352"/>
          <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20845"/>
          <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21339"/>
          <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21279"/>
          <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21139"/>
          <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21210"/>
          <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20570"/>
          <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21286"/>
          <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21252"/>
          <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21321"/>
          <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21268"/>
          <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:20425"/>
          <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.13" test_ref="oval:org.mitre.oval:tst:21179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8330" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3877" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3877"/>
        <description>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:14.552-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:17.683-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:04.365-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8305" version="3" class="vulnerability">
      <metadata>
        <title>HP Enterprise Cluster Master Toolkit (ECMT) running on HP-UX, Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4184" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4184"/>
        <description>Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:01:58.090-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:17.102-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:03.661-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02464">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SG-Oracle-Tool.CM-ORACLE is installed" test_ref="oval:org.mitre.oval:tst:21214"/>
            <criterion comment="SG-Sybase-Tool.CM-SYBASE is installed" test_ref="oval:org.mitre.oval:tst:20958"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_40230 is installed" test_ref="oval:org.mitre.oval:tst:20313"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02464">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SG-Oracle-Tool.CM-ORACLE is installed" test_ref="oval:org.mitre.oval:tst:21214"/>
            <criterion comment="SG-Sybase-Tool.CM-SYBASE is installed" test_ref="oval:org.mitre.oval:tst:20958"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_40229 is installed" test_ref="oval:org.mitre.oval:tst:20702"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8275" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3871" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871"/>
        <description>Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:09.897-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:15.872-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:02.345-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8259" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2671" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2671"/>
        <description>The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:19.616-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:14.920-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:01.295-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8073" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2674" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2674"/>
        <description>Integer overflow in javaws.exe in Sun Java Web Start in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 allows context-dependent attackers to execute arbitrary code via a crafted JPEG image that is not properly handled during display to a splash screen, which triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:21.885-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:12.245-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:58.399-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8022" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2670" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2670"/>
        <description>The audio system in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to java.lang.System properties by (1) untrusted applets and (2) Java Web Start applications, which allows context-dependent attackers to obtain sensitive information by reading these properties.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:18.830-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:10.076-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:57.052-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7986" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running VRTSweb, Remote Execution of Arbitrary Code, Increase of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3027" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3027"/>
        <description>VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; Veritas Storage Foundation for Windows High Availability (SFWHA) 4.3MP2, 5.0, 5.0RP1a, 5.0RP2, 5.1, and 5.1AP1; Veritas Storage Foundation for High Availability (SFHA) 3.5; Veritas Storage Foundation for Oracle (SFO) 4.1, 5.0, and 5.0.1; Veritas Storage Foundation for DB2 4.1 and 5.0; Veritas Storage Foundation for Sybase 4.1 and 5.0; Veritas Storage Foundation for Oracle Real Application Cluster (SFRAC) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Manager (SFM) 1.0, 1.0 MP1, 1.1, 1.1.1Ux, 1.1.1Win, and 2.0; Veritas Cluster Server (VCS) 3.5, 4.0, 4.1, and 5.0; Veritas Cluster Server One (VCSOne) 2.0, 2.0.1, and 2.0.2; Veritas Application Director (VAD) 1.1 and 1.1 Platform Expansion; Veritas Cluster Server Management Console (VCSMC) 5.1, 5.5, and 5.5.1; Veritas Storage Foundation Cluster File System (SFCFS) 3.5, 4.0, 4.1, and 5.0; Veritas Storage Foundation Cluster File System for Oracle RAC (SFCFS RAC) 5.0; Veritas Command Central Storage (CCS) 4.x, 5.0, and 5.1; Veritas Command Central Enterprise Reporter (CC-ER) 5.0 GA, 5.0 MP1, 5.0 MP1RP1, and 5.1; Veritas Command Central Storage Change Manager (CC-SCM) 5.0 and 5.1; and Veritas MicroMeasure 5.0 does not properly validate authentication requests, which allows remote attackers to trigger the unpacking of a WAR archive, and execute arbitrary code in the contained files, via crafted data to TCP port 14300.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:40.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:04.616-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:09.612-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:56.592-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02480">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="VRTSweb.VRTSWEB is installed" test_ref="oval:org.mitre.oval:tst:20656"/>
          <criteria negate="true" operator="OR" comment="Patch PHCO_40519 and PHCO_40520 are installed">
            <criterion comment="Patch PHCO_40519 is installed" test_ref="oval:org.mitre.oval:tst:21311"/>
            <criterion comment="Patch PHCO_40520 is installed" test_ref="oval:org.mitre.oval:tst:21357"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02480">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="VRTSweb.VRTSWEB is installed" test_ref="oval:org.mitre.oval:tst:20656"/>
          <criterion negate="true" comment="Patch PHCO_40518 is installed" test_ref="oval:org.mitre.oval:tst:21249"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7913" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3875" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3875"/>
        <description>The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:12.989-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:07.963-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:54.930-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:785" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX usermod(1M) Local Unauthorized Access.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-05-07T12:00:00.048-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-07T12:01:40.074-04:00">INTERIM</status_change>
            <status_change date="2007-05-23T15:05:52.817-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.466-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.680-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02102" date="2008-07-14T10:21:00.322-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:22:19.346-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:7877"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_34764 is installed" test_ref="oval:org.mitre.oval:tst:8277"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_33142 is installed" test_ref="oval:org.mitre.oval:tst:8598"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02102">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8212"/>
          <criterion negate="true" comment="Patch PHCO_34763 is installed" test_ref="oval:org.mitre.oval:tst:8081"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7791" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813"/>
        <description>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-23T16:01:39.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:01:59.312-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:04.485-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:51.492-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02479">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:21063"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:20996"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:21235"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:20957"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:21276"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:21208"/>
          <criterion comment="CIFS-CFSM.CFSM-KRN version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:21284"/>
          <criterion comment="CIFS-CFSM.CFSM-RUN version is less than A.02.03.05 or equal to A.02.04 or A.02.04a" test_ref="oval:org.mitre.oval:tst:20487"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7750" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3867" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867"/>
        <description>Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:07.668-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:01.814-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:48.760-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02503">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20287"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21009"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20865"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21181"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21269"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20785"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20932"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20739"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21166"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20975"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21157"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:20888"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21180"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21161"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21041"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21186"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.24.00" test_ref="oval:org.mitre.oval:tst:21112"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20942"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21163"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21239"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21147"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21050"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21152"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20695"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20858"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20653"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21240"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21098"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21241"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:20456"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.19.00" test_ref="oval:org.mitre.oval:tst:21285"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20892"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21053"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21191"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20877"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20556"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20758"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20683"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21228"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21149"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21107"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20916"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21272"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:21105"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.06.00" test_ref="oval:org.mitre.oval:tst:20746"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7723" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java, Remote Increase in Privilege, Denial of Service and Other Vulnerabilities</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2672" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672"/>
        <description>The proxy mechanism implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, does not prevent access to browser cookies by untrusted (1) applets and (2) Java Web Start applications, which allows remote attackers to hijack web sessions via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-22T17:00:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2010-04-02T15:02:20.390-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:00:59.776-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:46.519-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02476">
        <criteria operator="OR">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21232"/>
          <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21134"/>
          <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21288"/>
          <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21280"/>
          <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21264"/>
          <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21236"/>
          <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21266"/>
          <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21217"/>
          <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21165"/>
          <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20296"/>
          <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20866"/>
          <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21114"/>
          <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21200"/>
          <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21131"/>
          <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21090"/>
          <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:20521"/>
          <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.23.00" test_ref="oval:org.mitre.oval:tst:21075"/>
          <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21193"/>
          <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20364"/>
          <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20326"/>
          <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21148"/>
          <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20488"/>
          <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21242"/>
          <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21197"/>
          <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20531"/>
          <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21198"/>
          <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21177"/>
          <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21138"/>
          <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20945"/>
          <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:21254"/>
          <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.17.00" test_ref="oval:org.mitre.oval:tst:20871"/>
          <criterion comment="Jdk60.JDK60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21155"/>
          <criterion comment="Jre60.JRE60-PA20W-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21289"/>
          <criterion comment="Jdk60.JDK60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20933"/>
          <criterion comment="Jdk60.JDK60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21178"/>
          <criterion comment="Jre60.JRE60-COM version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20303"/>
          <criterion comment="Jre60.JRE60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20896"/>
          <criterion comment="Jre60.JRE60-IPF32-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21293"/>
          <criterion comment="Jre60.JRE60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20784"/>
          <criterion comment="Jre60.JRE60-IPF64-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21176"/>
          <criterion comment="Jre60.JRE60-PA20 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20635"/>
          <criterion comment="Jdk60.JDK60-IPF32 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21039"/>
          <criterion comment="Jre60.JRE60-PA20-HS version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:20661"/>
          <criterion comment="Jdk60.JDK60-IPF64 version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21008"/>
          <criterion comment="Jre60.JRE60-PA20W version is less than 1.6.0.05.00" test_ref="oval:org.mitre.oval:tst:21199"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:772" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Usermod Local Unauthorized Access Vulnerability instead of usermod Recursive Ownership Error.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1248" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1248"/>
        <description>Unspecified vulnerability in usermod in HP-UX B.11.00, B.11.11, and B.11.23, when run with certain options that involve a new home directory, might cause usermod to change the ownership of all directories and files under the new directory, which might result in less secure permissions than intended.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-03-18T07:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-03-22T11:10:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-04-06T06:31:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-05-03T10:06:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Added CVE reference. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:27:00.650-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-19T20:42:53.692-04:00">INTERIM</status_change>
            <modified comment="Updated definition title. Implemented by Jon Baker of The MITRE Corporation." date="2007-03-19T20:42:00.035-04:00">
              <contributor organization="Security-Database">Nabil Ouchn</contributor>
            </modified>
            <status_change date="2007-04-10T13:44:28.730-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:766" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Trusted Mode remshd, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3565" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3565"/>
        <description>Unknown vulnerability in remshd daemon in HP-UX B.11.00, B.11.11, and B.11.23 while running in "Trusted Mode" allows remote attackers to gain unauthorized system access via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.246-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.446-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02072" date="2008-07-14T10:21:00.631-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:24:15.648-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.468-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33791 is installed" test_ref="oval:org.mitre.oval:tst:8349"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:8168"/>
          <criterion negate="true" comment="Patch PHNE_33790 is installed" test_ref="oval:org.mitre.oval:tst:8118"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02072">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:8005"/>
          <criterion negate="true" comment="Patch PHNE_33792 is installed" test_ref="oval:org.mitre.oval:tst:8139"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7652" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3292" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3292"/>
        <description>Unspecified vulnerability in PHP before 5.2.11, and 5.3.x before 5.3.1, has unknown impact and attack vectors related to "missing sanity checks around exif processing."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:48.291-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:54.549-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:56.406-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:760" version="1" class="vulnerability">
      <metadata>
        <title>Apache HTTP Byte-range DoS Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2728" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2728"/>
        <description>The byte-range filter in Apache 2.0 before 2.0.54 allows remote attackers to cause a denial of service (memory consumption) via an HTTP header with a large Range field.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7550" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2798" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2798"/>
        <description>Stack-based buffer overflow in the rename_principal_2_svc function in kadmind for MIT Kerberos 1.5.3, 1.6.1, and other versions allows remote authenticated users to execute arbitrary code via a crafted request to rename a principal.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:55.148-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:52.073-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:55.203-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7450" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-1321" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1321"/>
        <description>The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:55.609-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:50.450-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:54.608-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7439" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4143" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4143"/>
        <description>PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.825-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:50.155-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:54.281-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7396" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3557" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3557"/>
        <description>The tempnam function in ext/standard/file.c in PHP before 5.2.12 and 5.3.x before 5.3.1 allows context-dependent attackers to bypass safe_mode restrictions, and create files in group-writable or world-writable directories, via the dir and prefix arguments.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:48.784-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:49.588-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.896-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7394" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3291" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3291"/>
        <description>The php_openssl_apply_verification_policy function in PHP before 5.2.11 does not properly perform certificate validation, which has unknown impact and attack vectors, probably related to an ability to spoof certificates.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:47.982-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:49.301-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:53.567-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:735" version="1" class="vulnerability">
      <metadata>
        <title>Apache Integer Overflow in pcre_compile.c</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Apache</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-2491" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2491"/>
        <description>Integer overflow in pcre_compile.c in Perl Compatible Regular Expressions (PCRE) before 6.2, as used in multiple products such as Python, Ethereal, and PHP, allows attackers to execute arbitrary code via quantifier values in regular expressions, which leads to a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
            <criteria operator="AND" comment="700 Series OS Release 11.00">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.00">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:2512"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="hpuxwsAPACHE is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2388"/>
        <criterion comment="hpuxwsAPACHE has a version greater than or equal (A|B).2.0.55.0" negate="true" test_ref="oval:org.mitre.oval:tst:2387"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7344" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2442" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2442"/>
        <description>The gssrpc__svcauth_gssapi function in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a zero-length RPC credential, which causes kadmind to free an uninitialized pointer during cleanup.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:54.124-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:45.352-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:52.295-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:728" version="4" class="vulnerability">
      <metadata>
        <title>HP-UX 11 Perl rmtree Race Condition</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Perl</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0448" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0448"/>
        <description>Race condition in the rmtree function in File::Path.pm in Perl before 5.8.4 allows local users to create arbitrary setuid binaries in the tree being deleted, a different vulnerability than CVE-2004-0452.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.495-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.663-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:48:00.580-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:49:04.605-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.449-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.789-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:41:03.259-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:35.508-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="OR">
        <criteria operator="AND" comment="Perl 5.6 or 5.8 vulnerable on 11.00, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="Perl version 5.6.0 is installed or 5.8.0 without revision G or later is installed" negate="false">
            <criterion comment="Perl 5.6.0 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3419"/>
            <criterion comment="Perl 5.8.0 (revision F or earlier) is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3902"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.00 or 11.11" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00 or 11.11" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision C or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3226"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.2 vulnerable on 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
            <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.2,revision E or earlier is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3635"/>
        </criteria>
        <criteria operator="AND" comment="Perl 5.8.3 vulnerable on 11.0, 11.11, or 11.23" negate="false">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00, 11.11, or 11.23" negate="false">
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.00" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.00" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.00" negate="false" test_ref="oval:org.mitre.oval:tst:3571"/>
              </criteria>
            </criteria>
            <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
              <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
                <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
              <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
                <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
                <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
              </criteria>
            </criteria>
          </criteria>
          <criterion comment="Perl 5.8.3,revision A is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3847"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7261" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4022" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:04:56.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:58.838-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:44.080-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:51.941-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:21277"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21460"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:21294"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40339 is installed" test_ref="oval:org.mitre.oval:tst:21189"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.015" test_ref="oval:org.mitre.oval:tst:20542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:726" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX 11.00 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:52.288-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:59.492-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:52:00.826-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:23.849-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:25.287-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.157-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.290-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:726 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:50.414-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:45.820-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.00">
          <criteria operator="AND" comment="700 Series OS Release 11.00">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.00">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_33395 is installed" test_ref="oval:org.mitre.oval:tst:3393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7257" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2813" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2813"/>
        <description>Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-04T14:16:08.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha Nargolkar</contributor>
            </submitted>
            <status_change date="2010-10-05T14:11:03.814-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:25.959-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:43.619-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02479 SSRT090212 rev.1">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11391"/>
            <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11048"/>
            <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11225"/>
            <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11197"/>
            <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11120"/>
            <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.04.01" test_ref="oval:org.mitre.oval:tst:11346"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02479 SSRT090212 rev.1">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11548"/>
            <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11809"/>
            <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11334"/>
            <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11446"/>
            <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11049"/>
            <criterion comment="CIFS-CFSM.CFSM-KRN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11672"/>
            <criterion comment="CIFS-CFSM.CFSM-RUN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11403"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02479 SSRT090212 rev.1">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11548"/>
            <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11809"/>
            <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11334"/>
            <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11446"/>
            <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.05" test_ref="oval:org.mitre.oval:tst:11049"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7256" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4018" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4018"/>
        <description>The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.336-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:43.312-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:51.623-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7131" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-2443" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2443"/>
        <description>Integer signedness error in the gssrpc__svcauth_unix function in svc_auth_unix.c in the RPC library in MIT Kerberos 5 (krb5) 1.6.1 and earlier might allow remote attackers to execute arbitrary code via a negative length value.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:35:23.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:54.660-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:40.960-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:50.727-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41168 is installed" test_ref="oval:org.mitre.oval:tst:20503"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
            <criterion comment="KRB5-Client.KRB5-IA32SLIB is installed" test_ref="oval:org.mitre.oval:tst:20792"/>
            <criterion comment="KRB5-Client.KRB5-IA64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21183"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41167 is installed" test_ref="oval:org.mitre.oval:tst:21355"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="KRB5-Client.KRB5-SHLIB is installed" test_ref="oval:org.mitre.oval:tst:21408"/>
            <criterion comment="KRB5-Client.KRB5-PRG is installed" test_ref="oval:org.mitre.oval:tst:21421"/>
            <criterion comment="KRB5-Client.KRB5-RUN is installed" test_ref="oval:org.mitre.oval:tst:21019"/>
            <criterion comment="KRB5-Client.KRB5-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:21027"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_41166 is installed" test_ref="oval:org.mitre.oval:tst:21374"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21391"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21255"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20686"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21334"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21081"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20956"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21369"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21120"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21060"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.10" test_ref="oval:org.mitre.oval:tst:21383"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02544">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21317"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:20710"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21337"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21431"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21330"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.08" test_ref="oval:org.mitre.oval:tst:21451"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7092" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File Modification</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2902" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2902"/>
        <description>Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:43:28.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:44.281-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:39.974-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:50.181-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21400"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7085" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4142"/>
        <description>The htmlspecialchars function in PHP before 5.2.12 does not properly handle (1) overlong UTF-8 sequences, (2) invalid Shift_JIS sequences, and (3) invalid EUC-JP sequences, which allows remote attackers to conduct cross-site scripting (XSS) attacks by placing a crafted byte sequence before a special character.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.584-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:39.694-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:49.830-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7050" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX running Software Distributor (sd), Local Privilege Increase, Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2712" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2712"/>
        <description>Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:20:18.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:02.544-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.858-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:49.421-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02552">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.GZIP is installed" test_ref="oval:org.mitre.oval:tst:20882"/>
            <criterion comment="SW-DIST.GZIP2 is installed" test_ref="oval:org.mitre.oval:tst:21440"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:21154"/>
            <criterion comment="SW-DIST.SD2-AGENT is installed" test_ref="oval:org.mitre.oval:tst:21351"/>
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:21306"/>
            <criterion comment="SW-DIST.SD2-CMDS is installed" test_ref="oval:org.mitre.oval:tst:21392"/>
            <criterion comment="SW-DIST.SD-EXAMPLES is installed" test_ref="oval:org.mitre.oval:tst:20660"/>
            <criterion comment="SW-DIST.SD-FAL is installed" test_ref="oval:org.mitre.oval:tst:21229"/>
            <criterion comment="SW-DIST.SD-PROVIDER is installed" test_ref="oval:org.mitre.oval:tst:21244"/>
            <criterion comment="SW-DIST.SD2-PROVIDER is installed" test_ref="oval:org.mitre.oval:tst:21422"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHCO_41201 and PHCO_41202 are installed">
            <criterion comment="Patch PHCO_41201 is installed" test_ref="oval:org.mitre.oval:tst:20517"/>
            <criterion comment="Patch PHCO_41202 is installed" test_ref="oval:org.mitre.oval:tst:21010"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02552">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="SW-DIST.GZIP is installed" test_ref="oval:org.mitre.oval:tst:20882"/>
            <criterion comment="SW-DIST.SD-AGENT is installed" test_ref="oval:org.mitre.oval:tst:21154"/>
            <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:21306"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_41200 is installed" test_ref="oval:org.mitre.oval:tst:21201"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7047" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3293" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3293"/>
        <description>Unspecified vulnerability in the imagecolortransparent function in PHP before 5.2.11 has unknown impact and attack vectors related to an incorrect "sanity check for the color index."</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:48.537-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.543-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:49.107-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7033" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File Modification</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-3548" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3548"/>
        <description>The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:43:28.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:44.460-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.321-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.824-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21400"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:7017" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Increase in Privilege, Arbitrary File Modification</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2693"/>
        <description>Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:43:28.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:44.009-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:38.095-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:48.590-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21400"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02541">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.29.01" test_ref="oval:org.mitre.oval:tst:21304"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6914" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Directory Server and Red Hat Directory Server for HP-UX, Local Disclosure of Information, Privilege Escalation</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-3282" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3282"/>
        <description>** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem.  When the candidate has been publicized, the details for this candidate will be provided.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T10:49:54.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:07:06.649-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:36.166-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:47.533-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02587">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="HpuxDirSvr.ADMSVR-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21397"/>
            <criterion comment="HpuxDirSvr.ADMSVR-SHARED version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20728"/>
            <criterion comment="HpuxDirSvr.CORE-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21489"/>
            <criterion comment="HpuxDirSvr.GUI-HELP version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20905"/>
            <criterion comment="HpuxDirSvr.GUI-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21453"/>
            <criterion comment="HpuxDirSvr.GUI-SHARED version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20988"/>
            <criterion comment="HpuxDirSvr.SLAPD-DEVEL version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20742"/>
            <criterion comment="HpuxDirSvr.SLAPD-RUN version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:21522"/>
            <criterion comment="HpuxDirSvr.SLAPD-SHARED version is less than B.08.10.03" test_ref="oval:org.mitre.oval:tst:20800"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02587">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RedHatDirSvr.ADMSVR-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21325"/>
            <criterion comment="RedHatDirSvr.ADMSVR-SHARED version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21413"/>
            <criterion comment="RedHatDirSvr.CORE-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21457"/>
            <criterion comment="RedHatDirSvr.GUI-HELP version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21498"/>
            <criterion comment="RedHatDirSvr.GUI-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21349"/>
            <criterion comment="RedHatDirSvr.GUI-SHARED version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21196"/>
            <criterion comment="RedHatDirSvr.SLAPD-DEVEL version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21502"/>
            <criterion comment="RedHatDirSvr.SLAPD-RUN version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:20565"/>
            <criterion comment="RedHatDirSvr.SLAPD-SHARED version is less than B.08.00.02" test_ref="oval:org.mitre.oval:tst:21333"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6892" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running sendmail, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-2261" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2261"/>
        <description>Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS hostname.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-01T14:30:46.000-05:00">
              <contributor organization="Hewlett-Packard">Aslesha</contributor>
            </submitted>
            <status_change date="2010-10-05T14:11:00.152-04:00">DRAFT</status_change>
            <status_change date="2010-10-25T04:00:21.132-04:00">INTERIM</status_change>
            <status_change date="2010-11-15T04:00:35.522-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495 SSRT090151 rev.2">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11578"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:11885"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40388 is installed" test_ref="oval:org.mitre.oval:tst:11506"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495 SSRT090151 rev.2">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SMAIL-811.INETSVCS-SMAIL version is less than SMAIL-813" test_ref="oval:org.mitre.oval:tst:11251"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02495 SSRT090151 rev.2">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11578"/>
          <criterion negate="true" comment="Patch PHNE_40393 is installed" test_ref="oval:org.mitre.oval:tst:11879"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:688" version="6" class="vulnerability">
      <metadata>
        <title>HP-UX 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.358-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.763-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.978-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:53:50.998-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:24.308-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:31.069-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.145-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:688 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:24.592-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:41.079-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion negate="true" comment="Patch PHNE_32606 is installed" test_ref="oval:org.mitre.oval:tst:3439"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6815" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0290" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290"/>
        <description>Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:04:56.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:59.165-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:33.753-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:46.617-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:21277"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21460"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:21294"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40339 is installed" test_ref="oval:org.mitre.oval:tst:21189"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.015" test_ref="oval:org.mitre.oval:tst:20542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6667" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-4017" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4017"/>
        <description>PHP before 5.2.12 and 5.3.x before 5.3.1 does not restrict the number of temporary files created when handling a multipart/form-data POST request, which allows remote attackers to cause a denial of service (resource exhaustion), and makes it easier for remote attackers to exploit local file inclusion vulnerabilities, via multiple requests, related to lack of support for the max_file_uploads directive.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:49.102-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:30.004-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:45.405-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6665" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running BIND, Remote Denial of Service (DoS), Unauthorized Disclosure of Information</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-0382" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0382"/>
        <description>ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819.  NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:04:56.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:59.379-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:29.725-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:45.113-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
            <criterion comment="BindUpgrade.BIND2-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21376"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-INETD is installed" test_ref="oval:org.mitre.oval:tst:21277"/>
            <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:21460"/>
            <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" test_ref="oval:org.mitre.oval:tst:21294"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_40339 is installed" test_ref="oval:org.mitre.oval:tst:21189"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BindUpgrade.BIND-UPGRADE version is less than C.9.3.2.7.0" test_ref="oval:org.mitre.oval:tst:21220"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02546">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="BINDv920.INETSVCS-BIND version is less than B.11.11.01.015" test_ref="oval:org.mitre.oval:tst:20542"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6655" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache with PHP, Remote Denial of Service (DoS), Unauthorized Access, Privileged Access, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2687" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2687"/>
        <description>The exif_read_data function in the Exif module in PHP before 5.2.10 allows remote attackers to cause a denial of service (crash) via a malformed JPEG image with invalid offset fields, a different issue than CVE-2005-3353.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-10-25T11:50:46.000-05:00">
              <contributor organization="Hewlett-Packard">Chandan M C</contributor>
            </submitted>
            <status_change date="2010-10-26T21:06:47.660-04:00">DRAFT</status_change>
            <status_change date="2010-11-15T04:00:29.397-05:00">INTERIM</status_change>
            <status_change date="2010-12-06T04:00:44.747-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxws22APCH32.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21433"/>
            <criterion comment="hpuxws22APCH32.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21494"/>
            <criterion comment="hpuxws22APACHE.PHP version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21310"/>
            <criterion comment="hpuxws22APACHE.PHP2 version is less than B.2.2.8.10" test_ref="oval:org.mitre.oval:tst:21341"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02543">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21353"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:20889"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21450"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.16" test_ref="oval:org.mitre.oval:tst:21415"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6628" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0580" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0580"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authentication realms, as demonstrated by a % (percent) value for the j_password parameter.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:22.921-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:39.735-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:12.924-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6564" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0781" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0781"/>
        <description>Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML."</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:23.143-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:37.592-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:10.401-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:651" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 Path MTU Discovery Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1060" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1060"/>
        <description>Multiple TCP/IP and ICMP implementations, when using Path MTU (PMTU) discovery (PMTUD), allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via forged ICMP ("Fragmentation Needed and Don't Fragment was Set") packets with a low next-hop MTU value, aka the "Path MTU discovery attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:51.103-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.450-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-22T17:43:00.954-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-22T17:44:10.985-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:23.230-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:651 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:06:15.190-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:39.616-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:648" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX wuftpd Privilege Escalation Vulnerability (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0148" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0148"/>
        <description>wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-30T07:20:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-02-01T09:08:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-07-03T12:56:00.000-04:00" comment="Added negate=true attribute to criteria sub-block to fix conversion error from OVAL 4.2 to OVAL 5.0">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-07-03T12:56:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-07T09:15:50.907-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.972-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:13.030-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.280-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:46:36.089-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:34.087-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
          <criteria operator="AND" comment="700 Series OS Release 11.23">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS2-RUN is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2472"/>
        <criteria operator="OR" comment="Either PHNE_30983 or PHNE_31732 is installed" negate="true">
          <criterion comment="Patch PHNE_30983 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2471"/>
          <criterion comment="Patch PHNE_31732 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2470"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6450" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0783" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0783"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted application that is loaded earlier than the target application.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:23.316-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:34.783-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:09.152-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6445" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Tomcat Servlet Engine, Remote Denial of Service (DoS), Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-5515" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5515"/>
        <description>Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences and the WEB-INF directory in a Request.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-11-13T16:45:29.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-09T17:16:22.453-05:00">DRAFT</status_change>
            <status_change date="2009-12-28T04:00:34.493-05:00">INTERIM</status_change>
            <status_change date="2010-01-18T04:00:08.845-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsTOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11215"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02466">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="hpuxws22TOMCAT.TOMCAT version is less than B.5.5.27.03" test_ref="oval:org.mitre.oval:tst:11062"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:642" version="3" class="vulnerability">
      <metadata>
        <title>HP-Samba DACL Remote Integer Overflow Vulnerability (CIFS A.02)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1154" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1154"/>
        <description>Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-01-13T02:24:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-01-25T07:30:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-02-22T08:27:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-03-09T12:19:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.413-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:44:54.135-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:33.713-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:2514"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2515"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:2513"/>
              <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:2511"/>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Any of the CIFS components has a version equal to A.02.01">
          <criterion comment="CIFS-Server.CIFS-RUN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2481"/>
          <criterion comment="CIFS-Server.CIFS-UTIL with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2480"/>
          <criterion comment="CIFS-Server.CIFS-ADMIN with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2479"/>
          <criterion comment="CIFS-Server.CIFS-LIB with version equal A.02.01 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2478"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6387" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0847" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0847"/>
        <description>The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.604-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:14.778-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:08.459-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6352" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running VERITAS File System (VRTSvxfs) or VERITAS Oracle Disk Manager (VRTSodm), Local Escalation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0207" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0207"/>
        <description>Unspecified vulnerability in HP-UX B.11.11 running VERITAS Oracle Disk Manager (VRTSodm) 3.5, B.11.23 running VRTSodm 4.1 or VERITAS File System (VRTSvxfs) 4.1, B.11.23 running VRTSodm 5.0 or VRTSvxfs 5.0, and B.11.31 running VRTSodm 5.0 allows local users to gain root privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-12-09T14:52:58.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-12-15T20:20:07.237-05:00">DRAFT</status_change>
            <status_change date="2010-01-04T04:01:45.505-05:00">INTERIM</status_change>
            <status_change date="2010-01-25T04:00:15.597-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02409">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="VRTSvxfs.VXFS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11292"/>
          <criterion negate="true" comment="Patch PHCO_39124 is installed" test_ref="oval:org.mitre.oval:tst:11283"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02409">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="VRTSvxfs or VRTSodm is vulnerable">
            <criteria operator="AND" comment="VRTSvxfs 4.1 or 5.0 is vulnerable">
              <criteria operator="OR" comment="VRTSvxfs 4.1 or 5.0 is installed">
                <criterion comment="VRTSvxfs.VXFS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11292"/>
                <criterion comment="VRTSvxfs.VXFS-RUN-PALIB is installed" test_ref="oval:org.mitre.oval:tst:11141"/>
                <criterion comment="VRTSvxfs.VXFS-PRG is installed" test_ref="oval:org.mitre.oval:tst:10996"/>
              </criteria>
              <criteria operator="OR" comment="PHCO_39027 not installed for 4.1, or patches PHCO_39103 and PHCO_39104 not installed for 5.0">
                <criterion negate="true" comment="Patch PHCO_39027 is installed" test_ref="oval:org.mitre.oval:tst:11186"/>
                <criteria negate="true" operator="AND">
                  <criterion comment="Patch PHCO_39103 is installed" test_ref="oval:org.mitre.oval:tst:10811"/>
                  <criterion comment="Patch PHCO_39104 is installed" test_ref="oval:org.mitre.oval:tst:11183"/>
                </criteria>
              </criteria>
            </criteria>
            <criteria operator="AND" comment="VRTSodm 4.1 or 5.0 is vulnerable">
              <criteria operator="OR" comment="VRTSodm 4.1 or 5.0 is installed">
                <criterion comment="VRTSodm.ODM-KRN is installed" test_ref="oval:org.mitre.oval:tst:11042"/>
                <criterion comment="VRTSodm.ODM-RUN is installed" test_ref="oval:org.mitre.oval:tst:11174"/>
                <criterion comment="VRTSodm.ODM-MAN is installed" test_ref="oval:org.mitre.oval:tst:10401"/>
              </criteria>
              <criteria operator="OR" comment="PHKL_39029 not installed for 4.1, or PHKL_38795 not installed for 5.0">
                <criterion negate="true" comment="Patch PHKL_39029 is installed" test_ref="oval:org.mitre.oval:tst:11218"/>
                <criterion negate="true" comment="Patch PHKL_38795 is installed" test_ref="oval:org.mitre.oval:tst:10890"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02409">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="VRTSvxfs or VRTSodm is vulnerable">
            <criteria operator="AND" comment="VRTSdom 5.0 is vulnerable">
              <criteria operator="OR">
                <criterion comment="VRTSodm.ODM-KRN is installed" test_ref="oval:org.mitre.oval:tst:11042"/>
                <criterion comment="VRTSodm.ODM-RUN is installed" test_ref="oval:org.mitre.oval:tst:11174"/>
                <criterion comment="VRTSodm.ODM-MAN is installed" test_ref="oval:org.mitre.oval:tst:10401"/>
              </criteria>
              <criterion comment="Patch PHKL_39130 is installed" test_ref="oval:org.mitre.oval:tst:11083"/>
            </criteria>
            <criteria operator="AND" comment="VRTSvxfs 5.0 is vulnerable">
              <criterion comment="VRTSvxfs.VXFS-RUN is installed" test_ref="oval:org.mitre.oval:tst:11292"/>
              <criteria negate="true" operator="AND" comment="Patch PHCO_38913 and PHCO_39132 are installed">
                <criterion comment="Patch PHCO_38913 is installed" test_ref="oval:org.mitre.oval:tst:11118"/>
                <criterion comment="Patch PHCO_39132 is installed" test_ref="oval:org.mitre.oval:tst:10878"/>
              </criteria>
            </criteria>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6328" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Role-Based Access Control (RBAC), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2682" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2682"/>
        <description>Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-10-07T11:33:53.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-10-09T14:07:00.581-04:00">DRAFT</status_change>
            <status_change date="2009-10-26T04:00:05.422-04:00">INTERIM</status_change>
            <status_change date="2009-11-16T04:00:19.006-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF is installed" test_ref="oval:org.mitre.oval:tst:10651"/>
            <criterion comment="RBAC.RBAC-RUN is installed" test_ref="oval:org.mitre.oval:tst:10540"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_40131 is installed" test_ref="oval:org.mitre.oval:tst:10732"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02457">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="RBAC.RBAC-CONF version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:9940"/>
            <criterion comment="RBAC.RBAC-RUN version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10583"/>
            <criterion comment="RBAC.RBAC-WEB version is less than B.11.23.06" test_ref="oval:org.mitre.oval:tst:10906"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6307" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running XNTP, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1252" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252"/>
        <description>Stack-based buffer overflow in the crypto_recv function in ntp_crypto.c in ntpd in NTP before 4.2.4p7 and 4.2.5 before 4.2.5p74, when OpenSSL and autokey are enabled, allows remote attackers to execute arbitrary code via a crafted packet containing an extension field.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:37.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:15.432-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:11.277-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:07.268-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10552"/>
          <criterion negate="true" comment="Patch PHNE_39872 is installed" test_ref="oval:org.mitre.oval:tst:9736"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:10571"/>
          <criterion negate="true" comment="Patch PHNE_39871 is installed" test_ref="oval:org.mitre.oval:tst:10557"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02437">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="NTP.NTP-RUN is installed" test_ref="oval:org.mitre.oval:tst:10348"/>
          <criterion negate="true" comment="Patch PHNE_39873 is installed" test_ref="oval:org.mitre.oval:tst:10276"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6301" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Kerberos, Remote Denial of Service (DoS), Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846"/>
        <description>The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:14.263-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:10.825-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10417"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9858"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10546"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:9864"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10283"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than D.1.6.2.01" test_ref="oval:org.mitre.oval:tst:10263"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10041"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10495"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10331"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than C.1.3.5.09" test_ref="oval:org.mitre.oval:tst:10556"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02421">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="krb5client.KRB5-64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10551"/>
            <criterion comment="krb5client.KRB5-PRG-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10305"/>
            <criterion comment="krb5client.KRB5-RUN-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10501"/>
            <criterion comment="krb5client.KRB5-SHLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10039"/>
            <criterion comment="krb5client.KRB5IA32SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10539"/>
            <criterion comment="krb5client.KRB5IA64SLIB-A version is less than E.1.6.2.03" test_ref="oval:org.mitre.oval:tst:10262"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6215" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX ttrace(2), Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-1427" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1427"/>
        <description>Unspecified vulnerability in HP-UX B.11.31 allows local users to cause a denial of service (system crash) via unknown vectors related to the ttrace system call.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-08-11T16:16:36.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-08-12T09:50:13.063-04:00">DRAFT</status_change>
            <status_change date="2009-08-31T04:00:09.428-04:00">INTERIM</status_change>
            <status_change date="2009-09-21T04:00:06.529-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02450">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:10434"/>
          <criterion comment="ProgSupport.PAUX-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:10443"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:10534"/>
        </criteria>
        <criterion negate="true" comment="Patch PHKL_40197 is installed" test_ref="oval:org.mitre.oval:tst:10541"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:616" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 swagentd Denial of Service</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>swagentd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-1389" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1389"/>
        <description>Unspecified vulnerability in swagentd in HP-UX B.11.00, B.11.04, and B.11.11 allows remote attackers to cause a denial of service (application crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:50.134-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.789-04:00">ACCEPTED</status_change>
            <modified comment="Added title and CVE reference." date="2007-02-23T16:06:00.705-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T16:06:46.731-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.697-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.876-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.891-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criteria operator="OR" comment="Installed B.11.11 software has not been patched for c00622788" negate="false">
          <criteria operator="AND" comment="DCE-Core.DCE-CORE-SHLIB is installed without PHSS_29964 or subsequent" negate="false">
            <criterion comment="DCE-Core.DCE-CORE-SHLIB is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3858"/>
            <criterion comment="Patch PHSS_29964 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3974"/>
          </criteria>
          <criteria operator="AND" comment="SW-DIST.SD-AGENT is installed without PHCO_28848 or subsequent" negate="false">
            <criterion comment="SW-DIST.SD-AGENT is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3857"/>
            <criterion comment="Patch PHCO_28848 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3831"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:615" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.11)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.969-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:57.625-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.850-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:49.873-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:22.517-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.11" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.11" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.11" negate="false" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
        </criteria>
        <criterion comment="WUFTP-26.INETSVCS-FTP with version less than B.11.11.01.006 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3641"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6118" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3283" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3283"/>
        <description>Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier allow remote attackers to cause a denial of service (memory consumption) via vectors involving (1) the authentication / bind phase and (2) anonymous LDAP search requests.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:48.650-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:53.320-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:33.216-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6115" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java JRE and JDK, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5236" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5236"/>
        <description>Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read local files via an untrusted application.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:23.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:51.754-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:43.086-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:11.357-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02284">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9416"/>
            <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9358"/>
            <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9394"/>
            <criterion comment="Jre15.JRE15-COM-DOC version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9414"/>
            <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8712"/>
            <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9270"/>
            <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8441"/>
            <criterion comment="Jdk15.JDK15-DEMO version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8831"/>
            <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8698"/>
            <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9265"/>
            <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9276"/>
            <criterion comment="Jre15.JRE15-PNV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9409"/>
            <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9220"/>
            <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9132"/>
            <criterion comment="Jre15.JRE15-PNV2-H version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9244"/>
            <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8716"/>
            <criterion comment="Jre15.JRE15-PWV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9101"/>
            <criterion comment="Jre15.JRE15-PWV2-H version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9436"/>
            <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9097"/>
            <criterion comment="Jdk15.JDK15-PNV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9408"/>
            <criterion comment="Jdk15.JDK15-PWV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8733"/>
            <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02284">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Jdk14.JDK14-PWV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9417"/>
            <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9170"/>
            <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9382"/>
            <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9405"/>
            <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8996"/>
            <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9007"/>
            <criterion comment="Jre14.JRE14-PNV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9402"/>
            <criterion comment="Jre14.JRE14-COM-DOC version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9437"/>
            <criterion comment="Jpi14.JPI14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8465"/>
            <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9252"/>
            <criterion comment="Jre14.JRE14-PNV2-H version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9371"/>
            <criterion comment="Jre14.JRE14-PWV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9363"/>
            <criterion comment="Jpi14.JPI14-COM-DOC version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8817"/>
            <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9400"/>
            <criterion comment="Jre14.JRE14-PWV2-H version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9420"/>
            <criterion comment="Jpi14.JPI14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9443"/>
            <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9390"/>
            <criterion comment="Jpi14.JPI14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9028"/>
            <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9325"/>
            <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9274"/>
            <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9201"/>
            <criterion comment="Jdk14.JDK14-DEMO version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9334"/>
            <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9034"/>
            <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9284"/>
            <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9319"/>
            <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9455"/>
            <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9303"/>
            <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9464"/>
            <criterion comment="Jdk14.JDK14-PNV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9307"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6111" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1355" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1355"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:53.603-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:42.704-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:10.994-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6105" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running B6848AB GTK+ Support Libraries, Local Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-2693" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2693"/>
        <description>HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privileges via files in /opt/gnome/src/GLib/.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:54.163-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:42.423-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:10.352-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01034">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          </criteria>
          <criterion comment="Gettext.GETTEXT-SRC version is less than 0.10.39.2.1" test_ref="oval:org.mitre.oval:tst:9045"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX01034">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="GTK+.GTK+-SRC version is less than 1.2.10.2.1" test_ref="oval:org.mitre.oval:tst:9172"/>
            <criterion comment="GLib.GLIB-SRC version is less than 1.2.10.2.1" test_ref="oval:org.mitre.oval:tst:8999"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6104" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running IPFilter, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0396" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0396"/>
        <description>Unspecified vulnerability in HP-UX B.11.23, when running IPFilter in combination with PHNE_34474, allows remote attackers to cause a denial of service (system crash) via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:49.345-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:53.048-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:32.435-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02181">
        <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        <criterion comment="IPF-HP.IPF-MIN is installed" test_ref="oval:org.mitre.oval:tst:8668"/>
        <criteria negate="true" operator="OR" comment="Patch PHNE_35545 and PHNE_35766 are installed">
          <criterion comment="Patch PHNE_35545 is installed" test_ref="oval:org.mitre.oval:tst:8875"/>
          <criterion comment="Patch PHNE_35766 is installed" test_ref="oval:org.mitre.oval:tst:9179"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6089" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4465" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465"/>
        <description>Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset.  NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-28T13:04:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:21.198-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:29.076-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:20.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9113"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8969"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9088"/>
            <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9123"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8990"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9023"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8708"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9120"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8971"/>
            <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9208"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9146"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6084" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Cross Site Scripting (XSS) or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2364" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2364"/>
        <description>The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-28T13:04:06.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-28T14:12:28.294-04:00">DRAFT</status_change>
            <status_change date="2008-09-15T04:00:28.002-04:00">INTERIM</status_change>
            <status_change date="2008-10-06T04:00:19.705-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02365">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="hpuxwsAPCH32.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9113"/>
            <criterion comment="hpuxwsAPACHE.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9070"/>
            <criterion comment="hpuxwsAPCH32.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8969"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8541"/>
            <criterion comment="hpuxwsAPACHE.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9168"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8818"/>
            <criterion comment="hpuxwsAPCH32.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9088"/>
            <criterion comment="hpuxwsAPCH32.APACHE2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9123"/>
            <criterion comment="hpuxwsAPACHE.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8707"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9221"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8990"/>
            <criterion comment="hpuxwsAPCH32.AUTH_LDAP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9023"/>
            <criterion comment="hpuxwsAPACHE.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8634"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8708"/>
            <criterion comment="hpuxwsAPACHE.PHP version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9224"/>
            <criterion comment="hpuxwsAPCH32.MOD_JK2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9120"/>
            <criterion comment="hpuxwsAPACHE.PHP2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8825"/>
            <criterion comment="hpuxwsAPACHE.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9049"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8971"/>
            <criterion comment="hpuxwsAPCH32.WEBPROXY version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9208"/>
            <criterion comment="hpuxwsAPCH32.MOD_PERL2 version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:9146"/>
            <criterion comment="hpuxwsAPACHE.APACHE version is less than B.2.0.59.07.01" test_ref="oval:org.mitre.oval:tst:8656"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6078" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2930" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2930"/>
        <description>Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denial of service (CPU consumption and search outage) via crafted LDAP search requests with patterns, related to a single-threaded regular-expression subsystem.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:49.621-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:52.468-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:31.819-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6077" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-4416" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4416"/>
        <description>Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-12-05T16:36:25.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-12-12T16:42:31.643-05:00">DRAFT</status_change>
            <status_change date="2008-12-29T04:00:38.394-05:00">INTERIM</status_change>
            <status_change date="2009-01-19T04:00:17.990-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02389">
        <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:9511"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9181"/>
        </criteria>
        <criterion negate="true" comment="Patch PHKL_38987 is installed" test_ref="oval:org.mitre.oval:tst:9485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6076" version="1" class="vulnerability">
      <metadata>
        <title>automountd can run user programs as root.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0210" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0210"/>
        <description>Automount daemon automountd allows local or remote users to gain privileges via shell metacharacters.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:54.422-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:41.254-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:09.037-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9910-104">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_20371 is installed" test_ref="oval:org.mitre.oval:tst:8490"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6067" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1900" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1900"/>
        <description>CRLF injection vulnerability in the FILTER_VALIDATE_EMAIL filter in ext/filter in PHP 5.2.0 and 5.2.1 allows context-dependent attackers to inject arbitrary e-mail headers via an e-mail address with a '\n' character, which causes a regular expression to ignore the subsequent part of the address string.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:54.701-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:40.429-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:07.722-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6056" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Apache, Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-3378" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3378"/>
        <description>The (1) session_save_path, (2) ini_set, and (3) error_log functions in PHP 4.4.7 and earlier, and PHP 5 5.2.3 and earlier, when invoked from a .htaccess file, allow remote attackers to bypass safe_mode and open_basedir restrictions and possibly execute arbitrary commands, as demonstrated using (a) php_value, (b) php_flag, and (c) directives in .htaccess.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:23.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:55.053-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:40.167-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:07.424-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02308">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00.2" test_ref="oval:org.mitre.oval:tst:9344"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02308">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00.2" test_ref="oval:org.mitre.oval:tst:9329"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6051" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the BIND executable</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0009" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0009"/>
        <description>Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:55.296-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.940-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:07.182-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9808-083">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_12957 is installed" test_ref="oval:org.mitre.oval:tst:9061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6037" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running LDAP-UX, Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1659" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1659"/>
        <description>Unspecified vulnerability in HP LDAP-UX vB.04.10 through vB.04.15 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:55.970-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.593-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:06.661-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02330">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="LdapUxClient.ADMIN-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9322"/>
          <criterion comment="LdapUxClient.CORE-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9278"/>
          <criterion comment="LdapUxClient.LDAP-C-SDK version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9218"/>
          <criterion comment="LdapUxClient.LDUX-ENG-A-MAN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:8631"/>
          <criterion comment="LdapUxClient.NATIVELDAP-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9384"/>
          <criterion comment="LdapUxClient.PAM-AUTHZ-RUN version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9415"/>
          <criterion comment="NisLdapServer.YPLDAP-SERVER version is less than B.04.17" test_ref="oval:org.mitre.oval:tst:9114"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6033" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-6589" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6589"/>
        <description>The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI, a different vulnerability than CVE-2007-5947.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:56.312-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.354-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:06.284-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02153">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criterion comment="Firefox.FFOX-COM version is less than 2.0.0.11" test_ref="oval:org.mitre.oval:tst:9300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6022" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0772" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0772"/>
        <description>Buffer overflows and other vulnerabilities in multiple Common Desktop Environment (CDE) modules in HP-UX 10.10 through 11.11 allow attackers to cause a denial of service and possibly gain additional privileges.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:51.351-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:51.956-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:31.150-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:9060"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_24098 is installed" test_ref="oval:org.mitre.oval:tst:8626"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHSS_24087 and PHSS_24091 are installed">
            <criterion comment="Patch PHSS_24087 is installed" test_ref="oval:org.mitre.oval:tst:9194"/>
            <criterion comment="Patch PHSS_24091 is installed" test_ref="oval:org.mitre.oval:tst:9148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_23797 is installed" test_ref="oval:org.mitre.oval:tst:9212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6002" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-1860" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1860"/>
        <description>mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes request URLs within the Apache HTTP Server before passing the URL to Tomcat, which allows remote attackers to access protected pages via a crafted prefix JkMount, possibly involving double-encoded .. (dot dot) sequences and directory traversal, a related issue to CVE-2007-0450.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:56.476-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:39.071-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:05.253-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criterion comment="hpuxwsAPACHE version is less than B.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9217"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02262">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="hpuxwsAPACHE version is less than A.2.0.59.00" test_ref="oval:org.mitre.oval:tst:9178"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:598" version="3" class="vulnerability">
      <metadata>
        <title>HP-UX Running xterm Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3779" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3779"/>
        <description>Unspecified vulnerability in xterm for HP-UX 11.00, 11.11, and 11.23 allows local users to gain privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-11-30T12:00:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2005-12-20T11:03:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-01-04T08:04:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-01-25T07:30:00.000-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.676-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.645-04:00">ACCEPTED</status_change>
            <modified comment="Criteria meets HP Security Bulletin HPSBUX02075" date="2008-07-14T10:21:00.902-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </modified>
            <status_change date="2008-07-14T10:23:55.918-04:00">INTERIM</status_change>
            <status_change date="2008-08-04T04:00:42.071-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34102 is installed" test_ref="oval:org.mitre.oval:tst:8317"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34160 is installed" test_ref="oval:org.mitre.oval:tst:8362"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02075">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="X11.X11-RUN-CL is installed" test_ref="oval:org.mitre.oval:tst:8371"/>
          <criterion negate="true" comment="Patch PHSS_34159 is installed" test_ref="oval:org.mitre.oval:tst:8389"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5971" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ftpd, Remote Privileged Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1668" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1668"/>
        <description>ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-12T16:30:32.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:35.905-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:19.712-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:38.867-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02356">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="InternetSrvcs.INETSVCS-RUN is installed" test_ref="oval:org.mitre.oval:tst:9029"/>
        <criterion negate="true" comment="Patch PHNE_38458 is installed" test_ref="oval:org.mitre.oval:tst:9107"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5966" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the BIND executable</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0011" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0011"/>
        <description>Denial of Service vulnerabilities in BIND 4.9 and BIND 8 Releases via CNAME record and zone transfer.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:57.169-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:38.552-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:04.005-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9808-083">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_12957 is installed" test_ref="oval:org.mitre.oval:tst:9061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:596" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX 11.11 or 11.23 ICMP Source Quench Attack Vulnerability</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0791" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0791"/>
        <description>Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack."  NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability.  While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.438-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.897-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-23T12:53:00.683-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-23T12:54:12.704-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.919-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:596 - Various corrections to comments and products to align with Authoring Style Guide" date="2011-04-22T23:54:00.899-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-04-23T00:04:49.880-04:00">INTERIM</status_change>
            <status_change date="2011-05-09T04:01:37.359-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criteria operator="OR" comment="An HPUX 11.11 or 11.23 is installed">
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.11">
            <criteria operator="AND" comment="700 Series OS Release 11.11">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.11">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            </criteria>
          </criteria>
          <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23">
            <criteria operator="AND" comment="700 Series OS Release 11.23">
              <criterion comment="700-series HP" test_ref="oval:org.mitre.oval:tst:3443"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
            <criteria operator="AND" comment="800 Series OS Release 11.23">
              <criterion comment="800-series HP" test_ref="oval:org.mitre.oval:tst:4124"/>
              <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            </criteria>
          </criteria>
        </criteria>
        <criterion comment="TOUR_PRODUCT.T-NET2-KRN with version less than A.03.00 is installed" test_ref="oval:org.mitre.oval:tst:3415"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5958" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running CDE, Local Increased Privilege, Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0551" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0551"/>
        <description>Buffer overflow in CDE Print Viewer (dtprintinfo) allows local users to execute arbitrary code by copying text from the clipboard into the Help window.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T16:54:45.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:51.818-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:48.724-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:27.315-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_24098 is installed" test_ref="oval:org.mitre.oval:tst:8626"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
          </criteria>
          <criteria negate="true" operator="OR" comment="Patch PHSS_24087 and PHSS_24091 are installed">
            <criterion comment="Patch PHSS_24087 is installed" test_ref="oval:org.mitre.oval:tst:9194"/>
            <criterion comment="Patch PHSS_24091 is installed" test_ref="oval:org.mitre.oval:tst:9148"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00151">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-HELP is installed" test_ref="oval:org.mitre.oval:tst:8963"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8914"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8754"/>
            <criterion comment="CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8916"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:9116"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:9155"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8653"/>
            <criterion comment="CDE.CDE-HELP-RUN is installed" test_ref="oval:org.mitre.oval:tst:9238"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8726"/>
            <criterion comment="CDE.CDE-ENG-A-MAN is installed" test_ref="oval:org.mitre.oval:tst:8927"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_23797 is installed" test_ref="oval:org.mitre.oval:tst:9212"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5948" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running ARPA Transport, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-4179" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4179"/>
        <description>Unspecified vulnerability in the Address and Routing Parameter Area (ARPA) transport functionality in HP-UX B.11.11 and B.11.23 allows local users to cause an unspecified denial of service via unknown vectors.  NOTE: this is probably different from CVE-2007-0916, but this is not certain due to lack of vendor details.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:57.513-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:38.216-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:03.659-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02247">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8495"/>
          <criterion negate="true" comment="Patch PHNE_35351 is installed" test_ref="oval:org.mitre.oval:tst:8979"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02247">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:8495"/>
          <criterion negate="true" comment="Patch PHNE_35766 is installed" test_ref="oval:org.mitre.oval:tst:9388"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5943" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running IPv6, Remote Denial of Service (DoS) and Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0418" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0418"/>
        <description>The IPv6 Neighbor Discovery Protocol (NDP) implementation in HP HP-UX B.11.11, B.11.23, and B.11.31 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity), read private network traffic, and possibly execute arbitrary code via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-09T11:35:10.000-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-02-13T17:02:03.519-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:14.203-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:12.881-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02407">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8804"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9533"/>
            <criterion comment="Networking.NET-RUN-64 is installed" test_ref="oval:org.mitre.oval:tst:9380"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9706"/>
            <criterion comment="Networking.NET-PRG is installed" test_ref="oval:org.mitre.oval:tst:9463"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:9660"/>
            <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:9657"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9696"/>
            <criterion comment="Networking.NET2-RUN is installed" test_ref="oval:org.mitre.oval:tst:9016"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_37897 is installed" test_ref="oval:org.mitre.oval:tst:9301"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02407">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9533"/>
            <criterion comment="Networking.NET-RUN-64 is installed" test_ref="oval:org.mitre.oval:tst:9380"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9706"/>
            <criterion comment="Networking.NET-PRG is installed" test_ref="oval:org.mitre.oval:tst:9463"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:9660"/>
            <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:9657"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9696"/>
            <criterion comment="OS-Core.SYS-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:9518"/>
            <criterion comment="Networking.NET-KRN is installed" test_ref="oval:org.mitre.oval:tst:9656"/>
            <criterion comment="OS-Core.CORE-KRN is installed" test_ref="oval:org.mitre.oval:tst:9522"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_37898 is installed" test_ref="oval:org.mitre.oval:tst:9286"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02407">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.SYS2-ADMIN is installed" test_ref="oval:org.mitre.oval:tst:8804"/>
            <criterion comment="Networking.NMS2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9533"/>
            <criterion comment="Networking.NET-RUN-64 is installed" test_ref="oval:org.mitre.oval:tst:9380"/>
            <criterion comment="OS-Core.CORE2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9706"/>
            <criterion comment="Networking.NET-RUN is installed" test_ref="oval:org.mitre.oval:tst:9660"/>
            <criterion comment="ProgSupport.C-INC is installed" test_ref="oval:org.mitre.oval:tst:9657"/>
            <criterion comment="Networking.NET2-KRN is installed" test_ref="oval:org.mitre.oval:tst:9696"/>
            <criterion comment="Networking.NET2-RUN is installed" test_ref="oval:org.mitre.oval:tst:9016"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_38680 is installed" test_ref="oval:org.mitre.oval:tst:9491"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5931" version="1" class="vulnerability">
      <metadata>
        <title>The vacation program erroneously passes parameters to sendmail.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0057" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0057"/>
        <description>Vacation program allows command execution by remote users through a sendmail command.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:57.786-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:37.137-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:03.069-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9811-087">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_16295 is installed" test_ref="oval:org.mitre.oval:tst:9393"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:593" version="5" class="vulnerability">
      <metadata>
        <title>HP-UX ftpd Remote Unauthorized Data Access (B.11.23)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
          <product>ftpd</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-3296" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3296"/>
        <description>The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-09-22T05:48:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-09-22T20:15:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:49.302-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:56.734-04:00">ACCEPTED</status_change>
            <modified comment="Added title." date="2007-02-25T23:52:00.734-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-02-25T23:52:28.751-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:21.562-04:00">ACCEPTED</status_change>
            <modified comment="modified patch test to only check for specific patch, checking for supersedence was incorrect and need a language change" date="2007-09-13T00:00:00.000-05:00">
              <contributor organization="Opsware, Inc.">Todd Dolinsky</contributor>
            </modified>
            <status_change date="2007-09-13T14:05:30.589-04:00">INTERIM</status_change>
            <status_change date="2007-10-02T08:08:12.534-04:00">ACCEPTED</status_change>
            <modified comment="Updated the datatype from 'string' to 'fileset_revision' to match Schematron rules." date="2010-09-02T11:23:00.297-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2010-09-02T11:41:53.480-04:00">INTERIM</status_change>
            <status_change date="2010-09-20T04:00:30.929-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="OR" comment="700 Series or 800 Series OS Release 11.23" negate="false">
          <criteria operator="AND" comment="700 Series OS Release 11.23" negate="false">
            <criterion comment="700-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:3443"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="AND" comment="800 Series OS Release 11.23" negate="false">
            <criterion comment="800-series HP" negate="false" test_ref="oval:org.mitre.oval:tst:4124"/>
            <criterion comment="HP Release B.11.23" negate="false" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
        </criteria>
        <criterion comment="InternetSrvcs.INETSVCS-RUN for B.11.23 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:3687"/>
        <criterion comment="Patch PHNE_33414 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:3428"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5920" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running rpcbind, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-0165" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0165"/>
        <description>Unspecified vulnerability in libnsl in Sun Solaris 8 and 9 allows remote attackers to cause a denial of service (crash) via malformed RPC requests that trigger a crash in rpcbind.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-22T12:50:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-29T13:59:02.797-04:00">DRAFT</status_change>
            <status_change date="2008-10-20T04:00:25.825-04:00">INTERIM</status_change>
            <status_change date="2008-11-10T04:00:08.358-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02370">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:9268"/>
            <criterion comment="NFS.NFS-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8790"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_37110 is installed" test_ref="oval:org.mitre.oval:tst:8791"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02370">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NFS.NFS-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:9268"/>
            <criterion comment="NFS.NFS-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8790"/>
          </criteria>
          <criterion negate="true" comment="Patch PHNE_36982 is installed" test_ref="oval:org.mitre.oval:tst:9288"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5899" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Java JRE and JDK, Remote Unauthorized</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5237" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5237"/>
        <description>Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local files via an untrusted application, aka "two vulnerabilities."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:58.010-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:36.173-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:01.859-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02284">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Jre15.JRE15-COM version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9416"/>
            <criterion comment="Jre15.JRE15-IPF64 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9358"/>
            <criterion comment="Jre15.JRE15-IPF64-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9394"/>
            <criterion comment="Jre15.JRE15-COM-DOC version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9414"/>
            <criterion comment="Jre15.JRE15-PA20 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8712"/>
            <criterion comment="Jre15.JRE15-PA20-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9270"/>
            <criterion comment="Jdk15.JDK15-COM version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8441"/>
            <criterion comment="Jdk15.JDK15-DEMO version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8831"/>
            <criterion comment="Jre15.JRE15-PA20W version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8698"/>
            <criterion comment="Jdk15.JDK15-IPF32 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9265"/>
            <criterion comment="Jre15.JRE15-PA20W-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9276"/>
            <criterion comment="Jre15.JRE15-PNV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9409"/>
            <criterion comment="Jdk15.JDK15-IPF64 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9220"/>
            <criterion comment="Jdk15.JDK15-PA20 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9132"/>
            <criterion comment="Jre15.JRE15-PNV2-H version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9244"/>
            <criterion comment="Jdk15.JDK15-PA20W version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8716"/>
            <criterion comment="Jre15.JRE15-PWV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9101"/>
            <criterion comment="Jre15.JRE15-PWV2-H version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9436"/>
            <criterion comment="Jre15.JRE15-IPF32 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9097"/>
            <criterion comment="Jdk15.JDK15-PNV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:9408"/>
            <criterion comment="Jdk15.JDK15-PWV2 version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8733"/>
            <criterion comment="Jre15.JRE15-IPF32-HS version is less than 1.5.0.11" test_ref="oval:org.mitre.oval:tst:8475"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02284">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="Jdk14.JDK14-PWV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9417"/>
            <criterion comment="Jdk14.JDK14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9170"/>
            <criterion comment="Jre14.JRE14-PA20W version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9382"/>
            <criterion comment="Jdk14.JDK14-PA20 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9405"/>
            <criterion comment="Jre14.JRE14-PA20W-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8996"/>
            <criterion comment="Jre14.JRE14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9007"/>
            <criterion comment="Jre14.JRE14-PNV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9402"/>
            <criterion comment="Jre14.JRE14-COM-DOC version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9437"/>
            <criterion comment="Jpi14.JPI14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8465"/>
            <criterion comment="Jre14.JRE14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9252"/>
            <criterion comment="Jre14.JRE14-PNV2-H version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9371"/>
            <criterion comment="Jre14.JRE14-PWV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9363"/>
            <criterion comment="Jpi14.JPI14-COM-DOC version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:8817"/>
            <criterion comment="Jre14.JRE14-IPF32-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9400"/>
            <criterion comment="Jre14.JRE14-PWV2-H version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9420"/>
            <criterion comment="Jpi14.JPI14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9443"/>
            <criterion comment="Jre14.JRE14-IPF64 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9390"/>
            <criterion comment="Jpi14.JPI14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9028"/>
            <criterion comment="Jre14.JRE14-IPF64-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9325"/>
            <criterion comment="Jdk14.JDK14-COM version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9274"/>
            <criterion comment="Jre14.JRE14-PA11 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9201"/>
            <criterion comment="Jdk14.JDK14-DEMO version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9334"/>
            <criterion comment="Jre14.JRE14-PA11-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9034"/>
            <criterion comment="Jdk14.JDK14-IPF32 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9284"/>
            <criterion comment="Jre14.JRE14-PA20 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9319"/>
            <criterion comment="Jdk14.JDK14-PA20W version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9455"/>
            <criterion comment="Jdk14.JDK14-IPF64 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9303"/>
            <criterion comment="Jre14.JRE14-PA20-HS version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9464"/>
            <criterion comment="Jdk14.JDK14-PNV2 version is less than 1.4.2.17.00" test_ref="oval:org.mitre.oval:tst:9307"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5896" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Firefox, Remote Unauthorized Access or Elevation of Privileges or Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5045" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5045"/>
        <description>Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter containing the Firefox "-chrome" argument.  NOTE: this is a related issue to CVE-2006-4965 and the result of an incomplete fix for CVE-2007-3670.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:58.838-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:35.853-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:01.494-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02153">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
        </criteria>
        <criterion comment="Firefox.FFOX-COM version is less than 2.0.0.11" test_ref="oval:org.mitre.oval:tst:9300"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5883" version="1" class="vulnerability">
      <metadata>
        <title>Potential Sec. Vulnerability in Java VM, JSSE, Plug-in,
          and Webstart. (rev.1)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1229" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1229"/>
        <description>X509TrustManager in (1) Java Secure Socket Extension (JSSE) in SDK and JRE 1.4.0 through 1.4.0_01, (2) JSSE before 1.0.3, (3) Java Plug-in SDK and JRE 1.3.0 through 1.4.1, and (4) Java Web Start 1.0 through 1.2 incorrectly calls the isClientTrusted method when determining server trust, which results in improper validation of digital certificate and allows remote attackers to (1) falsely authenticate peers for SSL or (2) incorrectly validate signed JAR files.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:24:59.297-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:35.559-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:01.013-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0301-239">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="VaultTS.VV-IWS-JAVA is installed" test_ref="oval:org.mitre.oval:tst:8939"/>
          <criterion negate="true" comment="Patch PHSS_28685 is installed" test_ref="oval:org.mitre.oval:tst:9447"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX0301-239">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="VaultTS.VV-IWS-JAVA is installed" test_ref="oval:org.mitre.oval:tst:8939"/>
          <criterion negate="true" comment="Patch PHSS_28686 is installed" test_ref="oval:org.mitre.oval:tst:9398"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5877" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2929" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2929"/>
        <description>Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Server Gateway (DSGW) web interface in Red Hat Directory Server 7.1 before SP7 and 8 EL4 and EL5, and Fedora Directory Server, allow remote attackers to inject arbitrary web script or HTML via input values that use % (percent) escaping.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:14.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:52.563-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:46.101-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:23.772-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5871" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running OpenSSL, Local Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5536" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5536"/>
        <description>Unspecified vulnerability in OpenSSL before A.00.09.07l on HP-UX B.11.11, B.11.23, and B.11.31 allows local users to cause a denial of service via unspecified vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:21.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:25:01.066-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:34.901-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:01:00.031-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02277">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9188"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9050"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9174"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9418"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9237"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9361"/>
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:8984"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.07l.006" test_ref="oval:org.mitre.oval:tst:9290"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02277">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9323"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9372"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9412"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:8993"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9373"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9056"/>
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9377"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.07l.007" test_ref="oval:org.mitre.oval:tst:9200"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02277">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="openssl.OPENSSL-CER version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:9356"/>
            <criterion comment="openssl.OPENSSL-CONF version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:9187"/>
            <criterion comment="openssl.OPENSSL-INC version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:9326"/>
            <criterion comment="openssl.OPENSSL-LIB version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:9277"/>
            <criterion comment="openssl.OPENSSL-MIS version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:8450"/>
            <criterion comment="openssl.OPENSSL-PRNG version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:9203"/>
            <criterion comment="openssl.OPENSSL-PVT version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:8528"/>
            <criterion comment="openssl.OPENSSL-RUN version is less than A.00.09.08d.003" test_ref="oval:org.mitre.oval:tst:9261"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5865" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-2928" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2928"/>
        <description>Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted Accept-Language HTTP header.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-02T12:41:13.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-09-09T10:51:53.166-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:45.418-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:23.158-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
            <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr7.NDS-SLAPD version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9039"/>
            <criterion comment="NetscapeDirSvr7.NDS-SLCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9086"/>
            <criterion comment="NetscapeDirSvr7.NDS-ADM version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9152"/>
            <criterion comment="NetscapeDirSvr7.NDS-BASE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9069"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSCLNT version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9124"/>
            <criterion comment="NetscapeDirSvr7.NDS-BSJRE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9216"/>
            <criterion comment="NetscapeDirSvr7.NDS-NC version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9226"/>
            <criterion comment="NetscapeDirSvr7.NDS-NSPERL version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9245"/>
            <criterion comment="NetscapeDirSvr7.NDS-PERLDAP version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9214"/>
            <criterion comment="NetscapeDirSvr7.NDS-SVCORE version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:8731"/>
            <criterion comment="NetscapeDirSvr7.NDS-RUN version is less than B.07.10.50" test_ref="oval:org.mitre.oval:tst:9111"/>
          </criteria>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02354">
          <criteria operator="OR" comment="platforms">
            <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
            <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          </criteria>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="NetscapeDirSvr6.NDS-SLCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9026"/>
            <criterion comment="NetscapeDirSvr6.NDS-SVCORE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9189"/>
            <criterion comment="NetscapeDirSvr6.NDS-ADM version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8769"/>
            <criterion comment="NetscapeDirSvr6.NDS-BASE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8977"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSCLNT version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9202"/>
            <criterion comment="NetscapeDirSvr6.NDS-BSJRE version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:9054"/>
            <criterion comment="NetscapeDirSvr6.NDS-NC version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8915"/>
            <criterion comment="NetscapeDirSvr6.NDS-NSPERL version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8861"/>
            <criterion comment="NetscapeDirSvr6.NDS-PERLDAP version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8423"/>
            <criterion comment="NetscapeDirSvr6.NDS-SLAPD version is less than B.06.21.70" test_ref="oval:org.mitre.oval:tst:8715"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5855" version="2" class="vulnerability">
      <metadata>
        <title>HP-UX Using libc, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1664" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1664"/>
        <description>Unspecified vulnerability in libc on HP HP-UX B.11.23 and B.11.31 allows remote attackers to cause a denial of service via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-07T10:53:22.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:29.603-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:11.754-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:34.470-04:00">ACCEPTED</status_change>
            <modified comment="Corrected the patch number for HP-UX B.11.31 based on the modification on HPSBUX02355" date="2009-11-16T17:18:00.073-05:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </modified>
            <status_change date="2009-11-16T17:19:30.081-05:00">INTERIM</status_change>
            <status_change date="2009-12-07T04:00:48.951-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
            <criterion comment="OS-Core.CORE-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8378"/>
            <criterion comment="OS-Core.CORE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:8981"/>
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38048 is installed" test_ref="oval:org.mitre.oval:tst:8563"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02355">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="OS-Core.C-MIN is installed" test_ref="oval:org.mitre.oval:tst:8917"/>
            <criterion comment="OS-Core.C-MIN-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8551"/>
            <criterion comment="OS-Core.CORE2-64SLIB is installed" test_ref="oval:org.mitre.oval:tst:8680"/>
            <criterion comment="OS-Core.CORE2-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:9084"/>
            <criterion comment="ProgSupport.PROG2-AUX is installed" test_ref="oval:org.mitre.oval:tst:8594"/>
            <criterion comment="ProgSupport.PROG-AX-64ALIB is installed" test_ref="oval:org.mitre.oval:tst:8703"/>
            <criterion comment="ProgSupport.PROG-MIN is installed" test_ref="oval:org.mitre.oval:tst:8906"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_38273 is installed" test_ref="oval:org.mitre.oval:tst:8692"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5833" version="1" class="vulnerability">
      <metadata>
        <title>Security vulnerability in the BIND executable</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0010" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0010"/>
        <description>Denial of Service vulnerability in BIND 8 Releases via maliciously formatted DNS messages.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-31T10:44:28.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:25:01.925-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:34.611-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:58.667-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9808-083">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_12957 is installed" test_ref="oval:org.mitre.oval:tst:9061"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5819" version="1" class="vulnerability">
      <metadata>
        <title>sendmail release 8.8.6 causes Denial of Service failures.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0478" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0478"/>
        <description>Denial of service in HP-UX sendmail 8.8.6 related to accepting connections.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-10-30T17:10:24.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-10-31T15:25:02.152-04:00">DRAFT</status_change>
            <status_change date="2008-11-17T04:00:34.386-05:00">INTERIM</status_change>
            <status_change date="2008-12-08T04:00:58.285-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9904-097">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHNE_17190 is installed" test_ref="oval:org.mitre.oval:tst:9335"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5814" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running System Administration Manager (SAM), Unintended Remote Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-1662" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1662"/>
        <description>Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify arbitrary files, related to an "empty systems list."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-31T12:40:22.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-08-11T11:11:31.251-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:09.394-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:32.273-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02286">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:8337"/>
            <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8776"/>
            <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:org.mitre.oval:tst:8945"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_36562 is installed" test_ref="oval:org.mitre.oval:tst:8901"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02286">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="InternetSrvcs.INETSVCS-BOOT is installed" test_ref="oval:org.mitre.oval:tst:8337"/>
            <criterion comment="OS-Core.UX-CORE is installed" test_ref="oval:org.mitre.oval:tst:8776"/>
            <criterion comment="SystemAdmin.SAM is installed" test_ref="oval:org.mitre.oval:tst:8945"/>
          </criteria>
          <criterion negate="true" comment="Patch PHCO_36563 is installed" test_ref="oval:org.mitre.oval:tst:8924"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5811" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX running HP CIFS Server (Samba), Remote Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5398" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5398"/>
        <description>Stack-based buffer overflow in the reply_netbios_packet function in nmbd/nmbd_packets.c in nmbd in Samba 3.0.0 through 3.0.26a, when operating as a WINS server, allows remote attackers to execute arbitrary code via crafted WINS Name Registration requests followed by a WINS Name Query request.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-06-30T13:13:25.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2008-07-02T17:04:30.472-04:00">DRAFT</status_change>
            <status_change date="2008-07-21T04:00:20.447-04:00">INTERIM</status_change>
            <status_change date="2008-08-11T04:00:44.118-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX02341">
        <criteria operator="OR" comment="platforms">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
        </criteria>
        <criteria operator="OR" comment="filesets tests">
          <criterion comment="CIFS-Server.CIFS-ADMIN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8191"/>
          <criterion comment="CIFS-Server.CIFS-DOC version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8249"/>
          <criterion comment="CIFS-Server.CIFS-LIB version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7825"/>
          <criterion comment="CIFS-Server.CIFS-MAN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7691"/>
          <criterion comment="CIFS-Server.CIFS-RUN version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:7982"/>
          <criterion comment="CIFS-Server.CIFS-UTIL version is less than A.02.03.04" test_ref="oval:org.mitre.oval:tst:8125"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5804" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running Software Distributor Local Elevation of Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2006-5558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5558"/>
        <description>Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument.  NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:32.634-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:41.781-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:36.330-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34814 is installed" test_ref="oval:org.mitre.oval:tst:8280"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SW-DIST.SD-CMDS version is less than B.11.23.0606.045" test_ref="oval:org.mitre.oval:tst:8496"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34539 is installed" test_ref="oval:org.mitre.oval:tst:8186"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02114">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="SW-DIST.SD-CMDS is installed" test_ref="oval:org.mitre.oval:tst:8300"/>
          <criterion negate="true" comment="Patch PHCO_34568 is installed" test_ref="oval:org.mitre.oval:tst:7611"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5791" version="1" class="vulnerability">
      <metadata>
        <title>HPUX Running useradd(1M), Local Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-0719" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0719"/>
        <description>Unspecified vulnerability in useradd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to access arbitrary files and directories via unknown vectors, a different issue than CVE-2008-1660.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-04-29T14:29:56.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-05-07T11:17:41.618-04:00">DRAFT</status_change>
            <status_change date="2009-05-25T04:01:46.634-04:00">INTERIM</status_change>
            <status_change date="2009-06-15T04:00:48.178-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38481 is installed" test_ref="oval:org.mitre.oval:tst:9730"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38490 is installed" test_ref="oval:org.mitre.oval:tst:9687"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02366">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="OS-Core.UX2-CORE is installed" test_ref="oval:org.mitre.oval:tst:10095"/>
          <criterion negate="true" comment="Patch PHCO_38482 is installed" test_ref="oval:org.mitre.oval:tst:9928"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5790" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX newgrp(1), Local Increased Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2001-0379" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0379"/>
        <description>Vulnerability in the newgrp program included with HP9000 servers running HP-UX 11.11 allows a local attacker to obtain higher access rights.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-10T16:22:35.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:33.169-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:41.563-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:36.043-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX00147">
        <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
        <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8406"/>
        <criterion negate="true" comment="Patch PHCO_23083 is installed" test_ref="oval:org.mitre.oval:tst:8588"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5789" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX libDtSvc, Local Increase in Privilege</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-1764" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-1764"/>
        <description>Buffer overflow in CDE libDtSvc on HP-UX B.11.00, B.11.04, B.11.11, and B.11.22 allows local users to gain root privileges via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:37.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:34.781-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:41.181-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:35.499-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8492"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8351"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8435"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8458"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_30167 is installed" test_ref="oval:org.mitre.oval:tst:8493"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.22" test_ref="oval:org.mitre.oval:tst:1015"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_28682 is installed" test_ref="oval:org.mitre.oval:tst:8526"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-TCH-B-MSG is installed" test_ref="oval:org.mitre.oval:tst:8408"/>
            <criterion comment="CDE.CDE-ITA-I-MSG is installed" test_ref="oval:org.mitre.oval:tst:8256"/>
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8435"/>
            <criterion comment="CDE.CDE-SCH-H-MSG is installed" test_ref="oval:org.mitre.oval:tst:8377"/>
            <criterion comment="CDE.CDE-SWE-I-MSG is installed" test_ref="oval:org.mitre.oval:tst:8580"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8492"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_28676 is installed" test_ref="oval:org.mitre.oval:tst:8368"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00308">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criteria operator="OR" comment="filesets tests">
            <criterion comment="CDE.CDE-ENG-A-MSG is installed" test_ref="oval:org.mitre.oval:tst:8474"/>
            <criterion comment="CDE.CDE-TT is installed" test_ref="oval:org.mitre.oval:tst:8492"/>
            <criterion comment="CDE.CDE-MIN is installed" test_ref="oval:org.mitre.oval:tst:7724"/>
            <criterion comment="CDE.CDE-RUN is installed" test_ref="oval:org.mitre.oval:tst:8351"/>
            <criterion comment="CDE.CDE-SHLIBS is installed" test_ref="oval:org.mitre.oval:tst:7942"/>
            <criterion comment="CDE.CDE-DTTERM is installed" test_ref="oval:org.mitre.oval:tst:8435"/>
            <criterion comment="CDE.CDE-FONTS is installed" test_ref="oval:org.mitre.oval:tst:8458"/>
          </criteria>
          <criterion negate="true" comment="Patch PHSS_28675 is installed" test_ref="oval:org.mitre.oval:tst:8507"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5788" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running shar(1), Local Execution of Arbitrary Code</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-1099" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-1099"/>
        <description>shar on HP-UX B.11.00, B.11.04, and B.11.11 creates temporary files with predictable names in /tmp, which allows local users to cause a denial of service and possibly execute arbitrary code via a symlink attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-08T17:01:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-14T10:51:35.478-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:40.872-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:35.134-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00304">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8504"/>
          <criterion negate="true" comment="Patch PHCO_2901 is installed" test_ref="oval:org.mitre.oval:tst:8574"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00304">
          <criterion comment="HP Release B.11.04" test_ref="oval:org.mitre.oval:tst:3294"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8504"/>
          <criterion negate="true" comment="Patch PHCO_29697 is installed" test_ref="oval:org.mitre.oval:tst:8309"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX00304">
          <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
          <criterion comment="OS-Core.CMDS-AUX is installed" test_ref="oval:org.mitre.oval:tst:8504"/>
          <criterion negate="true" comment="Patch PHCO_28954 is installed" test_ref="oval:org.mitre.oval:tst:8532"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5783" version="1" class="vulnerability">
      <metadata>
        <title>Buffer overflows in Software Distributor (SD) commands.</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-1999-0688" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0688"/>
        <description>Buffer overflows in HP Software Distributor (SD) for HPUX 10.x and 11.x.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-11T14:41:52.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-15T15:26:17.742-04:00">DRAFT</status_change>
            <status_change date="2008-08-04T04:00:40.631-04:00">INTERIM</status_change>
            <status_change date="2008-08-25T04:00:34.885-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND" comment="Criteria meets Security Bulletin HPSBUX9907-101">
        <criterion comment="HP Release B.11.00" test_ref="oval:org.mitre.oval:tst:3571"/>
        <criterion negate="true" comment="Patch PHCO_18183 is installed" test_ref="oval:org.mitre.oval:tst:8705"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5780" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running bootpd, Remote Denial of Service (DoS)</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2009-2679" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2679"/>
        <description>Unspecified vulnerability in bootpd in HP HP-UX B.11.11, B.11.23, and B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-09-16T13:58:26.000-04:00">
              <contributor organization="Hewlett-Packard">Pai Peng</contributor>
            </submitted>
            <status_change date="2009-09-22T21:48:49.747-04:00">DRAFT</status_change>
            <status_change date="2009-10-12T04:00:06.852-04:00">INTERIM</status_change>
            <status_change date="2009-11-02T04:00:07.330-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:9955"/>
          <criterion negate="true" comment="Patch PHNE_39668 is installed" test_ref="oval:org.mitre.oval:tst:10775"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="InternetSrvcs.INETSVCS2-BOOT is installed" test_ref="oval:org.mitre.oval:tst:9955"/>
          <criterion negate="true" comment="Patch PHNE_39700 is installed" test_ref="oval:org.mitre.oval:tst:10717"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02458">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8260"/>
          <criterion comment="DHCPv4.DHCPV4-RUN is installed" test_ref="oval:org.mitre.oval:tst:10679"/>
          <criterion negate="true" comment="Patch PHNE_39443 is installed" test_ref="oval:org.mitre.oval:tst:9859"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5779" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Running logins(1M), Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2007-5008" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5008"/>
        <description>The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileges when certain "password issues" are not detected.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-03T16:09:04.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
            <status_change date="2008-07-07T14:19:40.397-04:00">DRAFT</status_change>
            <status_change date="2008-07-28T04:00:27.092-04:00">INTERIM</status_change>
            <status_change date="2008-08-18T04:00:57.487-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP Release B.11.11" test_ref="oval:org.mitre.oval:tst:3704"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36809 is installed" test_ref="oval:org.mitre.oval:tst:8204"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP-UX B.11.31" test_ref="oval:org.mitre.oval:tst:8138"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36003 is installed" test_ref="oval:org.mitre.oval:tst:8254"/>
        </criteria>
        <criteria operator="AND" comment="Criteria meets HP Security Bulletin HPSBUX02259">
          <criterion comment="HP Release B.11.23" test_ref="oval:org.mitre.oval:tst:3901"/>
          <criterion comment="SOE.SOE is installed" test_ref="oval:org.mitre.oval:tst:7374"/>
          <criterion negate="true" comment="Patch PHCO_36808 is installed" test_ref="oval:org.mitre.oval:tst:8264"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:5775" version="1" class="vulnerability">
      <metadata>
        <title>HP-UX Ignite-UX, Remote Unauthorized Access</title>
        <affected family="unix">
          <platform>HP-UX 11</platform>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0952" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0952"/>
        <description>HP-UX B.11.00 through B.11.23, when running Ignite-UX and using the add_new_client command, causes the TFTP server to set world-writable permissions on part of the directory tree, which allows remote attackers to modify data or cause disk consumption.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-07-07T16:38:38.000-04:00">
              <contributor organization="Hewlett-Packard">Michael Wood</contributor>
            </submitted>
      
