<?xml version="1.0" encoding="UTF-8"?>
<oval_definitions xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#windows windows-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#independent independent-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5">
  <generator>
    <oval:product_name>The OVAL Repository</oval:product_name>
    <oval:schema_version>5.10</oval:schema_version>
    <oval:timestamp>2012-01-27T05:09:52.258-05:00</oval:timestamp>
  </generator>
  <definitions>
    <definition id="oval:org.mitre.oval:def:5881" version="6" class="vulnerability">
      <metadata>
        <title>GDI+ BMP Integer Overflow Vulnerability</title>
        <affected family="windows">
          <product>Microsoft Office 2003</product>
          <product>Microsoft Office 2007</product>
          <product>Microsoft Office Visio 2002</product>
          <product>Microsoft Office XP</product>
          <product>Microsoft PowerPoint Viewer</product>
          <product>Microsoft SQL Server 2005</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2008-3015" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3015"/>
        <description>Integer overflow in gdiplus.dll in GDI+ in Microsoft Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 2003, Works 8, Digital Image Suite 2006, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2, Report Viewer 2005 SP1 and 2008, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a BMP image file with a malformed BitMapInfoHeader that triggers a buffer overflow, aka "GDI+ BMP Integer Overflow Vulnerability."</description>
        <oval_repository>
          <dates>
            <submitted date="2008-09-09T13:58:00">
              <contributor organization="Secure Elements, Inc.">Sudhir Gandhe</contributor>
            </submitted>
            <status_change date="2008-09-12T12:49:06.488-04:00">DRAFT</status_change>
            <status_change date="2008-09-29T04:00:47.054-04:00">INTERIM</status_change>
            <status_change date="2008-10-20T04:00:24.376-04:00">ACCEPTED</status_change>
            <modified comment="Changed product &quot;Office 2002&quot; to &quot;Office XP&quot;" date="2010-01-14T15:49:00.152-05:00">
              <contributor organization="The MITRE Corporation">Mike Lah</contributor>
            </modified>
            <status_change date="2010-01-14T15:49:21.160-05:00">INTERIM</status_change>
            <status_change date="2010-02-01T04:00:13.923-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:5881 - Added LDR support for WinVista and Win2008, MSSQL 2005 SP2 inclusion &amp; updated version in ste:4158" date="2011-12-05T13:24:00.281-05:00">
              <contributor organization="SecPod Technologies">Pradeep R B</contributor>
            </modified>
            <status_change date="2011-12-05T13:29:05.296-05:00">INTERIM</status_change>
            <status_change date="2011-12-26T04:02:50.026-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:12103 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:37.424-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:03.906-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Vulnerable Office XP">
          <extend_definition comment="Microsoft Office XP is installed" definition_ref="oval:org.mitre.oval:def:663"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Office 2003">
          <extend_definition comment="Microsoft Office 2003 is installed" definition_ref="oval:org.mitre.oval:def:233"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Office 2007">
          <extend_definition comment="Microsoft Office 2007 is installed" definition_ref="oval:org.mitre.oval:def:1211"/>
          <criterion comment="Ogl.dll version is less than 12.0.6325.5000" test_ref="oval:org.mitre.oval:tst:9231"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable Office Visio 2002 SP2">
          <extend_definition comment="Microsoft Office Visio 2002 SP2 is installed" definition_ref="oval:org.mitre.oval:def:692"/>
          <criterion comment="Mso.dll version is less than 10.0.6844.0" test_ref="oval:org.mitre.oval:tst:9255"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable PowerPoint Viewer">
          <extend_definition comment="Microsoft PowerPoint Viewer is installed" definition_ref="oval:org.mitre.oval:def:6014"/>
          <criterion comment="GDIPlus.dll version is less than 11.0.8230.0" test_ref="oval:org.mitre.oval:tst:9205"/>
        </criteria>
        <criteria operator="AND" comment="Vulnerable SQL Server 2005 SP2">
          <criteria operator="OR" comment="SQL Server 2005 SP2">
            <criteria operator="AND" comment="SQL Server 2005 SP2">
              <extend_definition comment="Microsoft SQL Server 2005 is installed" definition_ref="oval:org.mitre.oval:def:6082"/>
              <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup\\SP equals 2" test_ref="oval:org.mitre.oval:tst:9558"/>
            </criteria>
            <extend_definition comment="Microsoft SQL Server 2005 SP2 is installed" definition_ref="oval:org.mitre.oval:def:8397"/>
          </criteria>
          <criteria operator="OR" comment="Vulnerable version of SP2 or hotfix">
            <criterion comment="Check if version of Sqlservr.exe is less than 2005.90.3073.0 (GDR)" test_ref="oval:org.mitre.oval:tst:77831"/>
            <criterion comment="Check if version of Sqlwb.exe is less than 2005.90.3282.0 (Hotfix/QFE)" test_ref="oval:org.mitre.oval:tst:77584"/>
          </criteria>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:8397" version="4" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2005 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft SQL Server 2005</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2005:sp2"/>
        <description>Microsoft SQL Server 2005 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-03-15T17:30:00.000-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </submitted>
            <status_change date="2010-03-25T17:31:14.313-04:00">DRAFT</status_change>
            <status_change date="2010-05-17T04:01:22.675-04:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:01:08.669-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11792 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:06.215-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:19.626-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="MS SQL Server 2005 SP2 is installed" test_ref="oval:org.mitre.oval:tst:20846"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:692" version="1" class="inventory">
      <metadata>
        <title>Microsoft Office Visio 2002 SP2 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:visio:2002:sp2"/>
        <description>The application Microsoft Office Visio 2002 SP2 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.484-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.914-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office Visio Professional 2002 with service pack 2" test_ref="oval:org.mitre.oval:tst:481"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:663" version="7" class="inventory">
      <metadata>
        <title>Microsoft Office XP is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:xp"/>
        <description>The application Microsoft Office XP is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:51.244-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:58.628-04:00">ACCEPTED</status_change>
            <modified comment="Added anchor to regex in obj:1339" date="2007-04-23T12:05:00.247-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-23T12:26:29.609-04:00">INTERIM</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.390-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:49.843-04:00">ACCEPTED</status_change>
            <modified comment="Now detects the non-OEM versions of Office XP." date="2008-11-10T10:51:00.927-05:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2008-11-10T10:57:34.946-05:00">INTERIM</status_change>
            <status_change date="2008-12-01T04:00:19.113-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:2179 - Fixed some regular expressions to conform to the Authoring style guide." date="2011-10-03T15:44:00.952-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-10-03T15:45:21.258-04:00">INTERIM</status_change>
            <status_change date="2011-10-24T04:00:27.403-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1339 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:41.130-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:18.840-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Microsoft Office XP OEM is installed" test_ref="oval:org.mitre.oval:tst:2327"/>
        <criterion comment="Microsoft Office XP is installed" test_ref="oval:org.mitre.oval:tst:9294"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6082" version="5" class="inventory">
      <metadata>
        <title>Microsoft SQL Server 2005 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <product>Microsoft SQL Server 2005</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:sql_server:2005"/>
        <description>Microsoft SQL Server 2005 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2009-02-10T16:00:00">
              <contributor organization="Gideon Technologies, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2009-02-13T17:01:34.144-05:00">DRAFT</status_change>
            <status_change date="2009-03-02T04:00:23.180-05:00">INTERIM</status_change>
            <status_change date="2009-03-23T04:00:18.474-04:00">ACCEPTED</status_change>
            <modified comment="Added tests that check against multiple instances of MS SQL 2005" date="2010-03-25T17:18:00.136-04:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-25T17:18:27.188-04:00">INTERIM</status_change>
            <status_change date="2010-05-17T04:00:10.814-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:11792 - Fixed several false positives by setting negate = true.  Also fixed several style issues." date="2011-12-28T21:13:00.551-05:00">
              <contributor organization="Symantec Corporation">Dragos Prisaca</contributor>
            </modified>
            <status_change date="2011-12-28T21:21:07.115-05:00">INTERIM</status_change>
            <status_change date="2012-01-16T04:03:12.166-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup\\Version is greater than 9.0.0.0" test_ref="oval:org.mitre.oval:tst:9665"/>
        <criterion comment="MS SQL Server 2005 is installed" test_ref="oval:org.mitre.oval:tst:21160"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6014" version="2" class="inventory">
      <metadata>
        <title>Microsoft PowerPoint Viewer is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:powerpoint_viewer"/>
        <description>The application Microsoft PowerPoint Viewer is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2008-08-13T09:28:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </submitted>
            <status_change date="2008-08-14T15:02:59.590-04:00">DRAFT</status_change>
            <status_change date="2008-09-01T04:01:22.609-04:00">INTERIM</status_change>
            <status_change date="2008-09-22T04:00:39.579-04:00">ACCEPTED</status_change>
            <modified comment="Removed Microsoft reference" date="2009-06-01T16:05:28.035-04:00">
              <contributor organization="The MITRE Corporation">Brendan Miles</contributor>
            </modified>
            <status_change date="2009-06-08T04:00:53.300-04:00">INTERIM</status_change>
            <status_change date="2009-06-29T04:00:46.912-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft PowerPoint Viewer is installed." test_ref="oval:org.mitre.oval:tst:9134"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:233" version="6" class="inventory">
      <metadata>
        <title>Microsoft Office 2003 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:2003"/>
        <description>The application Microsoft Office 2003 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-07-25T12:05:33">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-10-07T09:15:44.461-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:15:51.460-04:00">ACCEPTED</status_change>
            <modified comment="Added CPE reference." date="2007-04-30T07:48:00.964-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-04-30T07:52:13.988-04:00">INTERIM</status_change>
            <modified comment="Corrected ste:449 to use a pattern match and allow a major version of 11 and not check for other version components. Implemented by Jon Baker of the MITRE Corporation." date="2007-05-07T08:38:00.445-04:00">
              <contributor organization="PatchLink Corporation">Ken Lassesen</contributor>
            </modified>
            <status_change date="2007-05-23T15:05:40.917-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:ste:449 - Made updates to MS09-073 - In ste:5428 corrected the version and updated comments to test ID tst:10574 &amp; authoring guide updates." date="2011-08-31T17:33:00.787-04:00">
              <contributor organization="SecPod Technologies">Rachana Shetty</contributor>
            </modified>
            <status_change date="2011-08-31T17:35:06.675-04:00">INTERIM</status_change>
            <status_change date="2011-09-15T10:59:31.916-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:418 - Corrected registry key" date="2011-10-28T22:29:00.246-04:00">
              <contributor organization="SecPod Technologies">Chandan S</contributor>
            </modified>
            <status_change date="2011-10-28T22:30:11.017-04:00">INTERIM</status_change>
            <status_change date="2011-11-14T04:00:19.697-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office 2003 is installed" test_ref="oval:org.mitre.oval:tst:487"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1211" version="2" class="inventory">
      <metadata>
        <title>Microsoft Office 2007 is installed</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Vista</platform>
          <product>Microsoft Office 2007</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:microsoft:office:2007"/>
        <description>The application Microsoft Office 2007 is installed.</description>
        <oval_repository>
          <dates>
            <submitted date="2007-03-05T09:15:44.461-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </submitted>
            <status_change date="2007-03-05T09:15:44.461-04:00">DRAFT</status_change>
            <status_change date="2007-03-21T16:16:45.739-04:00">INTERIM</status_change>
            <status_change date="2007-04-10T13:44:19.356-04:00">ACCEPTED</status_change>
            <modified comment="Changed tst:3839 to check a different registry key to determine if Office 2007 is installed." date="2007-05-09T21:24:00.183-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-05-09T21:25:56.329-04:00">INTERIM</status_change>
            <modified comment="Corrected cpe name in reference." date="2007-05-23T15:38:00.055-04:00">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2007-06-08T21:36:34.361-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria>
        <criterion comment="Microsoft Office 2007 is installed" test_ref="oval:org.mitre.oval:tst:3839"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:12031" version="5" class="vulnerability">
      <metadata>
        <title>Vulnerability in IPMI dissector in Wireshark</title>
        <affected family="windows">
          <product>Wireshark</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2010-2993" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2993"/>
        <description>The IPMI dissector in Wireshark 1.2.0 through 1.2.9 allows remote attackers to cause a denial of service (infinite loop) via unknown vectors.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-08-16T18:01:02">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </submitted>
            <status_change date="2010-08-16T15:47:40.635-04:00">DRAFT</status_change>
            <status_change date="2010-09-06T04:11:46.792-04:00">INTERIM</status_change>
            <status_change date="2010-09-27T04:00:27.287-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:12031 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:23.184-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:08.140-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <extend_definition comment="Wireshark is installed on the system." definition_ref="oval:org.mitre.oval:def:6589"/>
        <criterion comment="Check for version of Wireshark installed on the system is 1.2.0 to 1.2.9" test_ref="oval:org.mitre.oval:tst:41775"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:6589" version="6" class="inventory">
      <metadata>
        <title>Wireshark is installed on the system.</title>
        <affected family="windows">
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <platform>Microsoft Windows Server 2008</platform>
          <platform>Microsoft Windows Vista</platform>
          <platform>Microsoft Windows 7</platform>
          <product>Wireshark</product>
        </affected>
        <reference source="CPE" ref_id="cpe:/a:wireshark:wireshark"/>
        <description>Wireshark is installed on the system.</description>
        <oval_repository>
          <dates>
            <submitted date="2010-05-17T15:11:12">
              <contributor organization="SecPod Technologies">Prabhu S A</contributor>
            </submitted>
            <status_change date="2010-05-17T16:08:16.678-05:00">DRAFT</status_change>
            <status_change date="2009-12-07T04:01:01.205-05:00">INTERIM</status_change>
            <status_change date="2009-12-28T04:00:38.570-05:00">ACCEPTED</status_change>
            <modified comment="Added Windows 2008 OS test" date="2010-03-08T14:57:00.444-05:00">
              <contributor organization="DTCC">J. Daniel Brown</contributor>
            </modified>
            <status_change date="2010-03-08T14:57:31.449-05:00">INTERIM</status_change>
            <status_change date="2010-06-07T04:00:04.029-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:7219 - Added test to check lower versions of Wireshark, anchored regular expression" date="2011-02-22T12:33:00.285-05:00">
              <contributor organization="SecPod Technologies">Preeti Subramanian</contributor>
            </modified>
            <status_change date="2011-02-22T12:35:54.504-05:00">INTERIM</status_change>
            <status_change date="2011-03-14T04:00:55.636-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:6589 - Spelling mistakes fixed in def:6391 &amp; def:6589 and associated comment updates." date="2011-05-02T19:06:00.721-04:00">
              <contributor organization="G2, Inc.">Shane Shaffer</contributor>
            </modified>
            <status_change date="2011-05-02T19:08:15.146-04:00">INTERIM</status_change>
            <status_change date="2011-05-23T04:00:19.194-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criterion comment="Check if lower version of Wireshark is installed" test_ref="oval:org.mitre.oval:tst:42216"/>
        <criterion comment="Wireshark is installed on the system" test_ref="oval:org.mitre.oval:tst:11132"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1067" version="3" class="vulnerability">
      <metadata>
        <title>Microsoft JScript Memory Corruption Vulnerability</title>
        <affected family="windows"/>
        <reference source="CVE" ref_id="CVE-2006-1313" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1313"/>
        <description>Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.</description>
        <oval_repository>
          <dates>
            <submitted date="2006-06-14T09:55:00.000-04:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </submitted>
            <status_change date="2006-06-14T07:51:00.000-04:00">DRAFT</status_change>
            <status_change date="2006-10-07T09:15:11.115-04:00">INTERIM</status_change>
            <status_change date="2006-10-24T09:14:58.565-04:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:def:1067 - Consolidated criteria for def:1067, 1644, 1785, and 2003." date="2011-01-13T14:04:00.159-05:00">
              <contributor organization="The MITRE Corporation">Nate Przybyszewski</contributor>
            </modified>
            <status_change date="2011-01-13T14:14:01.378-05:00">INTERIM</status_change>
            <status_change date="2011-01-31T04:00:03.086-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria operator="OR">
        <criteria operator="AND" comment="Software section">
          <criterion comment="the version of Jscript.dll is greater than or equal to 5.5.0.0" test_ref="oval:org.mitre.oval:tst:42119"/>
          <criterion comment="the version of Jscript.dll is less than 5.6.0.8831" test_ref="oval:org.mitre.oval:tst:1206"/>
        </criteria>
        <criterion comment="the version of Jscript.dll is less than 5.1.0.12512" test_ref="oval:org.mitre.oval:tst:792"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:961" version="2" class="vulnerability" deprecated="true">
      <metadata>
        <title>Microsoft Data Access Components SQL-DMO Buffer Overflow (Test 1)</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0353" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0353"/>
        <description>Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-05-04T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-05-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-06-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="split out the MDAC and file version tests from the compound test">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Deprecating duplicate definition for CVE-2003-0353" date="2010-05-05T12:00:00.000-05:00">
              <contributor organization="Symantec Corporation">Josh Turpin</contributor>
            </modified>
            <status_change date="2010-05-05T12:00:00.000-05:00">DEPRECATED</status_change>
          </dates>
          <status>DEPRECATED</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Microsoft Data Access Components 2.5 is installed" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" test_ref="oval:org.mitre.oval:tst:1396"/>
        <criterion comment="Patch Q823718 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:1395"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:844" version="1" class="vulnerability">
      <metadata>
        <title>MSN Messenger Remote File Access Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>MSN Messenger</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0122" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0122"/>
        <description>Microsoft MSN Messenger 6.0 and 6.1 does not properly handle certain requests, which allows remote attackers to read arbitrary files.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <modified date="2004-03-30T12:00:00.000-04:00" comment="Fixed the path for both versions of the file to look at the correct registry key to determine the location of the 'Program Files' folder..">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criteria operator="AND" comment="Microsoft MSN Messenger 6.0 or 6.1 (but less than 6.1.0211) is installed">
          <criterion comment="the version of msgsc.dll is greater than 6.0.0.0" negate="false" test_ref="oval:org.mitre.oval:tst:1591"/>
          <criterion comment="the version of msgsc.dll is less than 6.1.0.211" negate="false" test_ref="oval:org.mitre.oval:tst:1590"/>
        </criteria>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:843" version="3" class="vulnerability">
      <metadata>
        <title>MS Outlook Argument Injection Local Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <product>Microsoft Outlook</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0121" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0121"/>
        <description>Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arbitrary programs.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-03-09T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-25T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-05-05T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-01-13T12:00:00.000-04:00" comment="modified wft-130 - Added path to the end of the registry key specified in the first component of the file path">
              <contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
            </modified>
            <status_change date="2005-01-20T12:57:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-02-16T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed obj:1070: filename was utlook.exe instead of outlook.exe." date="2007-01-22T14:51:00.798-05:00">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2007-01-22T14:52:28.908-05:00">INTERIM</status_change>
            <status_change date="2007-02-20T13:41:01.279-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Outlook 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:1595"/>
        <criterion comment="the version of outlook.exe is less than 10.00.5709.0000" negate="false" test_ref="oval:org.mitre.oval:tst:1594"/>
        <criterion comment="the patch kb828040 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1593"/>
        <criterion comment="Microsoft Office XP Service Pack 3 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:1592"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:695" version="3" class="vulnerability">
      <metadata>
        <title>MS Excel 2002 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-16 - wft-16 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2419) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1377 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:51.621-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2420"/>
        <criterion comment="the version of excel.exe is less than 10.0.5815.0" negate="false" test_ref="oval:org.mitre.oval:tst:2419"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:675" version="1" class="vulnerability">
      <metadata>
        <title>MS Excel 97 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-14 - wft-14 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2434) fixed: xcel.exe to excel.exe.  Thanks to Rob Hollis of ThreatGuard.">
              <contributor organization="The MITRE Corporation">Matthew Wojcik</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Excel 97 is installed" test_ref="oval:org.mitre.oval:tst:2435"/>
        <criterion comment="the version of excel.exe is less than 8.00.01.9904" test_ref="oval:org.mitre.oval:tst:2434"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:668" version="3" class="vulnerability">
      <metadata>
        <title>MS Word 2002 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2003-11-19T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-22 by correcting literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:34.081-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.5815.0" negate="false" test_ref="oval:org.mitre.oval:tst:2449"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:636" version="3" class="vulnerability">
      <metadata>
        <title>MS Excel 2000 Malicious Macro Security Bypass Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0821" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0821"/>
        <description>Microsoft Excel 97, 2000, and 2002 allows remote attackers to execute arbitrary code via a spreadsheet with a malicious XLM (Excel 4) macro that bypasses the macro security model.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-15 - wft-15 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-08T03:12:00.000-04:00" comment="Filename typo in obj:662 (referenced by tst:2484) fixed: xcel.exe to excel.exe.">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2006-08-08T03:12:00.000-04:00">INTERIM</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-10-07T09:15:50.673-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
        <criterion comment="the version of excel.exe is less than 9.0.0.8216" negate="false" test_ref="oval:org.mitre.oval:tst:2484"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:586" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 98 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 98</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-10-16T04:13:00.000-04:00" comment="Modified test 2528 to use obj:492 rather than obj:1443 since they were the same and this definition was the only reference to obj:1443.">
              <contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
            </modified>
            <status_change date="2006-10-16T04:13:00.000-04:00">INTERIM</status_change>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Word 98 is installed" test_ref="oval:org.mitre.oval:tst:2529"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9716" test_ref="oval:org.mitre.oval:tst:2528"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:585" version="1" class="vulnerability">
      <metadata>
        <title>MS Word 97 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 97</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-17 - wft-17 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T12:01:00.000-04:00">INTERIM</status_change>
            <modified date="2005-04-20T12:00:00.000-04:00" comment="Corrected unknown test">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <modified comment="Incorrect notes element updated to match comment" date="2008-02-28T09:54:00.107-05:00">
              <contributor organization="Secure Elements, Inc.">Dragos Prisaca</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Word 97 is installed" test_ref="oval:org.mitre.oval:tst:2531"/>
        <criterion comment="the version of winword.exe is less than 8.0.0.9315" test_ref="oval:org.mitre.oval:tst:2530"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:553" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.6 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:26.904-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:19.427-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of odbcbcp.dll is less than 2000.80.747.0" negate="false" test_ref="oval:org.mitre.oval:tst:2564"/>
        <criterion comment="the version of sqlsrv32.dll is less than 2000.80.747.0" negate="false" test_ref="oval:org.mitre.oval:tst:2563"/>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:525" version="2" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.5 Broadcast Response Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0903" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0903"/>
        <description>Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-01-13T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-03-25T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.717-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:57:27.859-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:18.770-05:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="the version of odbcbcp.dll is less than 3.70.11.46" negate="false" test_ref="oval:org.mitre.oval:tst:2575"/>
        <criterion comment="the version of sqlsrv32.dll is less than 3.70.11.46" negate="false" test_ref="oval:org.mitre.oval:tst:2574"/>
        <criterion comment="the patch q832483 is installed" negate="true" test_ref="oval:org.mitre.oval:tst:2573"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4234" version="2" class="vulnerability">
      <metadata>
        <title>Word 2003 Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:24.734-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of winword.exe is less than 11.0.6502.0" negate="false" test_ref="oval:org.mitre.oval:tst:713"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:4226" version="1" class="vulnerability">
      <metadata>
        <title>Excel 2002 File Handler Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0846"/>
        <description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-18T12:11:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1377 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
          </dates>
          <status>INTERIM</status>
        </oval_repository>
      </metadata>
      <criteria operator="AND">
        <criterion comment="Excel 2002 is installed" test_ref="oval:org.mitre.oval:tst:2420"/>
        <criterion comment="Service Pack 2 or less for Windows Office XP" test_ref="oval:org.mitre.oval:tst:340"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:420" version="5" class="vulnerability">
      <metadata>
        <title>Word 2003 (wordview) Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:24.499-04:00">ACCEPTED</status_change>
            <modified date="2006-10-12T16:02:00.000-04:00" comment="Fixed filename typo in obj:1517 (referenced by tst:2648): ordview.exe to wordview.exe.">
              <contributor organization="Assuria Ltd.">Chris Wood</contributor>
            </modified>
            <status_change date="2006-10-12T16:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:39.458-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1517 - In obj:1517 for Office Word Viewer is updated by adding new variable and object to make it work. Earlier obj:1517 was referring to OfficeWord object path" date="2011-07-18T15:27:00.494-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-18T15:28:21.074-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:42.408-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of wordview.exe is less than 11.0.6506.0" negate="false" test_ref="oval:org.mitre.oval:tst:2648"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:3573" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.1 Remote Data Services Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows NT</platform>
          <product>Microsoft Data Access Components 2.1</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for Microsoft Data Access Components 2.1 since this definition is dependent on the Microsoft Data Access Components version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed title." date="2007-03-02T18:58:00.105-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-02T18:59:08.122-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:17.458-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.220-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:54:19.864-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:14.142-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:27:04.626-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:20.879-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.1 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:403"/>
        <criterion comment="the version of msadco.dll is less than 2.12.5118.0" negate="false" test_ref="oval:org.mitre.oval:tst:402"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:336" version="3" class="vulnerability">
      <metadata>
        <title>MS Word 2000 Macro Names Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2003-0820" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0820"/>
        <description>Microsoft Word 97, 98(J), 2000, and 2002, and Microsoft Works Suites 2001 through 2004, do not properly check the length of the "Macro names" data value, which could allow remote attackers to execute arbitrary code via a buffer overflow attack.</description>
        <oval_repository>
          <dates>
            <submitted date="2003-11-19T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Christine Walzer</contributor>
            </submitted>
            <status_change date="2004-03-09T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-04-11T12:00:00.000-04:00" comment="modified wft-19 - wft-19 corrected literal string">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </modified>
            <status_change date="2005-04-11T08:48:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-04-27T12:07:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:21.120-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8216" negate="false" test_ref="oval:org.mitre.oval:tst:2692"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:294" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.6 Remote Data Services Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.6</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for Microsoft Data Access Components 2.6 since this definition is dependent on the Microsoft Data Access Components version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Standardized title." date="2007-03-02T19:00:00.375-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-02T19:01:00.393-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:15.008-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.220-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:54:19.542-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:10.176-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:27:04.258-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:19.709-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.6 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2717"/>
        <criterion comment="the version of msadco.dll is less than 2.62.9119.1" negate="false" test_ref="oval:org.mitre.oval:tst:2716"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2730" version="5" class="vulnerability">
      <metadata>
        <title>Microsoft Data Access Components 2.5 Remote Data Services Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <product>Microsoft Data Access Components 2.5</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2002-1142" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1142"/>
        <description>Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-08-24T12:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
            </submitted>
            <status_change date="2004-08-25T12:00:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-09-09T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-09-29T12:00:00.000-04:00">ACCEPTED</status_change>
            <modified date="2005-02-28T12:00:00.000-04:00" comment="removed the test for windows NT and added a test for Microsoft Data Access Components 2.5 since this definition is dependent on the Microsoft Data Access Components version and not the platform">
              <contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
            </modified>
            <status_change date="2005-03-02T08:52:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-03-23T08:09:00.000-04:00">ACCEPTED</status_change>
            <modified comment="Fixed title." date="2007-03-02T18:54:00.290-05:00">
              <contributor organization="ThreatGuard, Inc.">Robert L. Hollis</contributor>
            </modified>
            <status_change date="2007-03-02T18:55:52.307-05:00">INTERIM</status_change>
            <status_change date="2007-03-21T16:17:13.972-04:00">ACCEPTED</status_change>
            <modified comment="set datatype to int" date="2007-10-25T16:45:00.220-04:00">
              <contributor organization="Opsware, Inc.">Jeff Cheng</contributor>
            </modified>
            <status_change date="2007-10-25T16:54:20.160-04:00">INTERIM</status_change>
            <status_change date="2007-11-13T12:01:09.900-05:00">ACCEPTED</status_change>
            <modified comment="References registry value for Common Files directory due to multilingual support" date="2008-04-14T11:07:00.270-04:00">
              <contributor organization="GFI Software">Clifford Farrugia</contributor>
            </modified>
            <status_change date="2008-04-14T12:27:08.969-04:00">INTERIM</status_change>
            <status_change date="2008-05-05T04:00:18.440-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Data Access Components 2.5 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2576"/>
        <criterion comment="the version of msadco.dll is less than 2.53.6202.0" negate="false" test_ref="oval:org.mitre.oval:tst:483"/>
        <criterion comment="Patch Q329414 Installed" negate="true" test_ref="oval:org.mitre.oval:tst:2715"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2685" version="2" class="vulnerability">
      <metadata>
        <title>Word 2000 Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:19.379-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8929" negate="false" test_ref="oval:org.mitre.oval:tst:591"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2673" version="2" class="vulnerability">
      <metadata>
        <title>Excel 2000 File Handler Code Execution Vulnerability</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Excel 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0846" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0846"/>
        <description>Unknown vulnerability in Microsoft Excel 2000, 2002, 2001 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via a malicious file containing certain parameters that are not properly validated.</description>
        <oval_repository>
          <dates>
            <submitted date="2004-10-18T12:07:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2004-10-20T02:35:00.000-04:00">DRAFT</status_change>
            <status_change date="2004-11-03T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2004-12-09T08:46:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1415 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:19.117-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Microsoft Office 2000 Professional Service Pack 3 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:489"/>
        <criterion comment="Excel 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2485"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2415" version="2" class="vulnerability">
      <metadata>
        <title>Word 2002 Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:18.191-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.6754.0" negate="false" test_ref="oval:org.mitre.oval:tst:621"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2216" version="2" class="vulnerability">
      <metadata>
        <title>Word 2000 Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2000</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1626 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:16.159-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2000 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2836"/>
        <criterion comment="the version of winword.exe is less than 9.0.0.8929" negate="false" test_ref="oval:org.mitre.oval:tst:591"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:2105" version="2" class="vulnerability">
      <metadata>
        <title>Word 2002 Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2002</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1510 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:29:15.377-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2002 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2641"/>
        <criterion comment="the version of winword.exe is less than 10.0.6754.0" negate="false" test_ref="oval:org.mitre.oval:tst:621"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1795" version="2" class="vulnerability">
      <metadata>
        <title>Word 2003 Malicious .doc Buffer Overflow</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Samba</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2004-0963" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0963"/>
        <description>Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file, including (1) an offset that triggers an out-of-bounds memory access, (2) a certain value that causes a large memory copy as triggered by an integer conversion error, and other values.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:58.870-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of winword.exe is less than 11.0.6502.0" negate="false" test_ref="oval:org.mitre.oval:tst:713"/>
      </criteria>
    </definition>
    <definition id="oval:org.mitre.oval:def:1236" version="5" class="vulnerability">
      <metadata>
        <title>Word 2003 (wordview) Malicious .doc Buffer Overflow II</title>
        <affected family="windows">
          <platform>Microsoft Windows 95</platform>
          <platform>Microsoft Windows 98</platform>
          <platform>Microsoft Windows ME</platform>
          <platform>Microsoft Windows NT</platform>
          <platform>Microsoft Windows 2000</platform>
          <platform>Microsoft Windows XP</platform>
          <platform>Microsoft Windows Server 2003</platform>
          <product>Microsoft Word 2003</product>
        </affected>
        <reference source="CVE" ref_id="CVE-2005-0558" ref_url="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0558"/>
        <description>Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.</description>
        <oval_repository>
          <dates>
            <submitted date="2005-09-15T04:00:00.000-04:00">
              <contributor organization="The MITRE Corporation">Matthew Burton</contributor>
            </submitted>
            <status_change date="2005-09-21T01:33:00.000-04:00">DRAFT</status_change>
            <status_change date="2005-10-12T05:49:00.000-04:00">INTERIM</status_change>
            <status_change date="2005-11-16T08:02:00.000-04:00">ACCEPTED</status_change>
            <modified date="2006-08-28T12:00:00.000-04:00" comment="modified obj 1518 to use xsi:nil instead of a .* pattern match">
              <contributor organization="Centennial Software">John Hoyland</contributor>
            </modified>
            <status_change date="2006-08-28T12:00:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-09-27T12:28:33.178-04:00">ACCEPTED</status_change>
            <modified date="2006-10-12T16:02:00.000-04:00" comment="Fixed filename typo in obj:1517 (referenced by tst:2648): ordview.exe to wordview.exe.">
              <contributor organization="Assuria Ltd.">Chris Wood</contributor>
            </modified>
            <status_change date="2006-10-12T16:02:00.000-04:00">INTERIM</status_change>
            <status_change date="2006-10-31T19:35:29.967-05:00">ACCEPTED</status_change>
            <modified comment="EDITED oval:org.mitre.oval:obj:1517 - In obj:1517 for Office Word Viewer is updated by adding new variable and object to make it work. Earlier obj:1517 was referring to OfficeWord object path" date="2011-07-18T15:27:00.494-04:00">
              <contributor organization="SecPod Technologies">Sharath S</contributor>
            </modified>
            <status_change date="2011-07-18T15:28:23.974-04:00">INTERIM</status_change>
            <status_change date="2011-08-08T04:00:19.460-04:00">ACCEPTED</status_change>
          </dates>
          <status>ACCEPTED</status>
        </oval_repository>
      </metadata>
      <criteria comment="Software section" operator="AND">
        <criterion comment="Word 2003 is installed" negate="false" test_ref="oval:org.mitre.oval:tst:2649"/>
        <criterion comment="the version of wordview.exe is less than 11.0.6506.0" negate="false" test_ref="oval:org.mitre.oval:tst:2648"/>
      </criteria>
    </definition>
  </definitions>
  <tests>
    <registry_test id="oval:org.mitre.oval:tst:20846" version="2" comment="MS SQL Server 2005 SP2 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:11792"/>
      <state state_ref="oval:org.mitre.oval:ste:6423"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:481" version="1" comment="Microsoft Office Visio Professional 2002 with service pack 2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:414"/>
      <state state_ref="oval:org.mitre.oval:ste:444"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:9294" version="2" comment="Microsoft Office XP is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1339"/>
      <state state_ref="oval:org.mitre.oval:ste:4586"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2327" version="5" comment="Microsoft Office XP OEM is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1339"/>
      <state state_ref="oval:org.mitre.oval:ste:2179"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:9665" version="1" comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup\\Version is greater than 9.0.0.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6714"/>
      <state state_ref="oval:org.mitre.oval:ste:4310"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:21160" version="2" comment="MS SQL Server 2005 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:11792"/>
      <state state_ref="oval:org.mitre.oval:ste:4310"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:9134" version="1" comment="Microsoft PowerPoint Viewer is installed." check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6307"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:487" version="4" comment="Microsoft Office 2003 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:418"/>
      <state state_ref="oval:org.mitre.oval:ste:449"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:3839" version="2" comment="Microsoft Office 2007 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1826"/>
      <state state_ref="oval:org.mitre.oval:ste:3218"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:9558" version="1" comment="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup\\SP equals 2" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6861"/>
      <state state_ref="oval:org.mitre.oval:ste:4777"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:9255" version="1" comment="Mso.dll version is less than 10.0.6844.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:467"/>
      <state state_ref="oval:org.mitre.oval:ste:4255"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:9231" version="1" comment="Ogl.dll version is less than 12.0.6325.5000" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6428"/>
      <state state_ref="oval:org.mitre.oval:ste:3438"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:9205" version="1" comment="GDIPlus.dll version is less than 11.0.8230.0" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:5941"/>
      <state state_ref="oval:org.mitre.oval:ste:4393"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:77831" version="2" comment="Check if version of Sqlservr.exe is less than 2005.90.3073.0 (GDR)" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:12081"/>
      <state state_ref="oval:org.mitre.oval:ste:17994"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:77584" version="1" comment="Check if version of Sqlwb.exe is less than 2005.90.3282.0 (Hotfix/QFE)" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:7341"/>
      <state state_ref="oval:org.mitre.oval:ste:18247"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:42216" version="1" comment="Check if lower version of Wireshark is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:15261"/>
      <state state_ref="oval:org.mitre.oval:ste:12246"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:11132" version="2" comment="Wireshark is installed on the system" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:7219"/>
      <state state_ref="oval:org.mitre.oval:ste:5622"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:41775" version="1" comment="Check for version of Wireshark installed on the system is 1.2.0 to 1.2.9" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:6871"/>
      <state state_ref="oval:org.mitre.oval:ste:11861"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:792" version="1" comment="the version of Jscript.dll is less than 5.1.0.12512" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:710"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:42119" version="1" comment="the version of Jscript.dll is greater than or equal to 5.5.0.0" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:12296"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1206" version="1" comment="the version of Jscript.dll is less than 5.6.0.8831" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:564"/>
      <state state_ref="oval:org.mitre.oval:ste:1078"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1396" version="1" comment="File %windir%\System32\odbcbcp.dll is less than 3.70.11.40" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:1258"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1395" version="1" deprecated="true" check="at least one" comment="DEPRECATED: Unused; Patch Q823718 Installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:962"/>
      <state state_ref="oval:org.mitre.oval:ste:1257"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1591" version="1" check="at least one" comment="the version of msgsc.dll is greater than 6.0.0.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1069"/>
      <state state_ref="oval:org.mitre.oval:ste:1445"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:1590" version="1" check="at least one" comment="the version of msgsc.dll is less than 6.1.0.211" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1069"/>
      <state state_ref="oval:org.mitre.oval:ste:1444"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1595" version="1" check="at least one" comment="Outlook 2002 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1072"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:1594" version="2" check="at least one" comment="the version of outlook.exe is less than 10.00.5709.0000" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1070"/>
      <state state_ref="oval:org.mitre.oval:ste:1448"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:1593" version="1" check="at least one" comment="the patch kb828040 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:334"/>
      <state state_ref="oval:org.mitre.oval:ste:1447"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:1592" version="1" check="at least one" comment="Microsoft Office XP Service Pack 3 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:334"/>
      <state state_ref="oval:org.mitre.oval:ste:1446"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2419" version="2" check="at least one" comment="the version of excel.exe is less than 10.0.5815.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2267"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:2435" version="1" comment="Excel 97 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test id="oval:org.mitre.oval:tst:2434" version="2" comment="the version of excel.exe is less than 8.00.01.9904" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2280"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2449" version="1" check="at least one" comment="the version of winword.exe is less than 10.0.5815.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2294"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2484" version="2" check="at least one" comment="the version of excel.exe is less than 9.0.0.8216" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:662"/>
      <state state_ref="oval:org.mitre.oval:ste:2328"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:2529" version="1" comment="Word 98 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent"/>
    <file_test id="oval:org.mitre.oval:tst:2528" version="2" comment="the version of winword.exe is less than 8.0.0.9716" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2365"/>
    </file_test>
    <unknown_test id="oval:org.mitre.oval:tst:2531" version="1" comment="Word 97 is installed" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes xmlns:oval1="http://oval.mitre.org/XMLSchema/oval-definitions-5">
        <note xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">Word 97 is installed.</note>
      </oval-def:notes>
    </unknown_test>
    <file_test id="oval:org.mitre.oval:tst:2530" version="1" comment="the version of winword.exe is less than 8.0.0.9315" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2366"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2564" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 2000.80.747.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2397"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2563" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 2000.80.747.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2396"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2575" version="1" check="at least one" comment="the version of odbcbcp.dll is less than 3.70.11.46" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:878"/>
      <state state_ref="oval:org.mitre.oval:ste:2408"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2574" version="1" check="at least one" comment="the version of sqlsrv32.dll is less than 3.70.11.46" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1351"/>
      <state state_ref="oval:org.mitre.oval:ste:2407"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2573" version="2" check="at least one" comment="the patch q832483 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1464"/>
      <state state_ref="oval:org.mitre.oval:ste:2406"/>
    </registry_test>
    <unknown_test id="oval:org.mitre.oval:tst:340" version="1" comment="Service Pack 2 or less for Windows Office XP" check_existence="at_least_one_exists" check="all" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#independent">
      <oval-def:notes xmlns:oval1="http://oval.mitre.org/XMLSchema/oval-definitions-5">
        <note xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5">Service Pack 2 or less for Windows Office XP needs regex involving strings and less than</note>
      </oval-def:notes>
    </unknown_test>
    <registry_test id="oval:org.mitre.oval:tst:2420" version="1" comment="Excel 2002 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1377"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:403" version="1" check="at least one" comment="Microsoft Data Access Components 2.1 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:377"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:402" version="2" check="at least one" comment="the version of msadco.dll is less than 2.12.5118.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:376"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:2692" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8216" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:2514"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2717" version="1" check="at least one" comment="Microsoft Data Access Components 2.6 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2538"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2716" version="2" check="at least one" comment="the version of msadco.dll is less than 2.62.9119.1" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:2537"/>
    </file_test>
    <file_test id="oval:org.mitre.oval:tst:483" version="2" check="at least one" comment="the version of msadco.dll is less than 2.53.6202.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:358"/>
      <state state_ref="oval:org.mitre.oval:ste:446"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2715" version="2" check="at least one" comment="Patch Q329414 Installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1562"/>
      <state state_ref="oval:org.mitre.oval:ste:2536"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2576" version="1" comment="Microsoft Data Access Components 2.5 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:359"/>
      <state state_ref="oval:org.mitre.oval:ste:2409"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:489" version="1" check="at least one" comment="Microsoft Office 2000 Professional Service Pack 3 is installed" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:420"/>
      <state state_ref="oval:org.mitre.oval:ste:451"/>
    </registry_test>
    <registry_test id="oval:org.mitre.oval:tst:2485" version="1" comment="Excel 2000 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1415"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:591" version="1" check="at least one" comment="the version of winword.exe is less than 9.0.0.8929" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:535"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2836" version="1" comment="Word 2000 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1626"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:621" version="1" check="at least one" comment="the version of winword.exe is less than 10.0.6754.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:561"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2641" version="1" comment="Word 2002 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1510"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:713" version="1" check="at least one" comment="the version of winword.exe is less than 11.0.6502.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:492"/>
      <state state_ref="oval:org.mitre.oval:ste:639"/>
    </file_test>
    <registry_test id="oval:org.mitre.oval:tst:2649" version="1" comment="Word 2003 is installed" check_existence="at_least_one_exists" check="at least one" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1518"/>
    </registry_test>
    <file_test id="oval:org.mitre.oval:tst:2648" version="3" check="at least one" comment="the version of wordview.exe is less than 11.0.6506.0" check_existence="at_least_one_exists" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <object object_ref="oval:org.mitre.oval:obj:1517"/>
      <state state_ref="oval:org.mitre.oval:ste:2474"/>
    </file_test>
  </tests>
  <objects>
    <registry_object id="oval:org.mitre.oval:obj:414" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>Software\Microsoft\Windows\CurrentVersion\Uninstall\{90510409-6D54-11D4-BEE3-00C04F990354}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1339" version="3" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^Software\\Microsoft\\Office\\10\.0\\Registration\\.*$</key>
      <name>ProductID</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:6714" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup</key>
      <name>Version</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:11792" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Microsoft SQL Server\\.*\\MSSQLServer\\CurrentVersion$</key>
      <name>CurrentVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:6307" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:868" var_check="all"/>
      <filename>pptview.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:418" version="2" comment="Microsoft Office 2003 is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Common\InstallRoot</key>
      <name>Path</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1826" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\12.0\Common\InstallRoot</key>
      <name>InstallCount</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:6861" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Microsoft SQL Server\90\DTS\Setup</key>
      <name>SP</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:467" version="2" comment="MSO.DLL for Office 10 in its installation directory" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:713" var_check="all"/>
      <filename>MSO.DLL</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:6428" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:553" var_check="all"/>
      <filename>Ogl.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:5941" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:107" var_check="all"/>
      <filename>Gdiplus.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:12081" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:678" var_check="all"/>
      <filename>sqlservr.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:12103" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="pattern match">^SOFTWARE\\Microsoft\\Microsoft SQL Server\\.*\\Setup$</key>
      <name>SQLPath</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:7341" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:154" var_check="all"/>
      <filename>sqlwb.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:15261" version="1" comment="The registry holds if lower version of wireshark is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ethereal</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:7219" version="2" comment="The registry holds if higher version of wireshark is installed" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wireshark</key>
      <name>DisplayName</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:6871" version="1" comment="The registry key that holds the version of the wireshark." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Wireshark</key>
      <name>DisplayVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:564" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200" var_check="all"/>
      <filename>jscript.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:962" version="1" deprecated="true" comment="DEPRECATED: Unused;" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\DataAccess\Q823718</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1069" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:246" var_check="all"/>
      <filename>msgsc.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:309" version="2" comment="The registry key that holds the location of the program files directory." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
      <name>ProgramFilesDir</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1072" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Office\10.0\Outlook\InstallRoot</key>
      <name operation="pattern match">.*</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1070" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:247" var_check="all"/>
      <filename>outlook.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:1071" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\OUTLOOK.EXE</key>
      <name>Path</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:334" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{90280409-6000-11D3-8CFE-0050048383C9}</key>
      <name>DisplayVersion</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:662" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:231" var_check="all"/>
      <filename>excel.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:663" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Excel.exe</key>
      <name>Path</name>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:878" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200" var_check="all"/>
      <filename>odbcbcp.dll</filename>
    </file_object>
    <file_object id="oval:org.mitre.oval:obj:1351" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:200" var_check="all"/>
      <filename>sqlsrv32.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:219" version="1" comment="This registry key identifies the system root." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows NT\CurrentVersion</key>
      <name>SystemRoot</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1464" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Updates\DataAccess\Q832483</key>
      <name operation="equals">IsInstalled</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1377" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Excel\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:358" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:212" var_check="all"/>
      <filename>msadco.dll</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:281" version="1" comment="The registry key that identifies the location of the common files directory." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion</key>
      <name>CommonFilesDir</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1562" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows NT\CurrentVersion\Hotfix\Q329414</key>
      <name operation="equals">Installed</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:359" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\DataAccess</key>
      <name>FullInstallVer</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:420" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key operation="equals">SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{00010409-78E1-11D2-B60F-006097C998E7}</key>
      <name operation="equals">DisplayVersion</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1415" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Excel\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1626" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\9.0\Word\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1510" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\10.0\Word\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:492" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:221" var_check="all"/>
      <filename>winword.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:493" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Winword.exe</key>
      <name>Path</name>
    </registry_object>
    <registry_object id="oval:org.mitre.oval:obj:1518" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Office\11.0\Word\InstallRoot</key>
      <name xsi:nil="true"/>
    </registry_object>
    <file_object id="oval:org.mitre.oval:obj:1517" version="3" comment="Object holds, if file wordview.exe is present" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <path var_ref="oval:org.mitre.oval:var:1946" var_check="all"/>
      <filename>wordview.exe</filename>
    </file_object>
    <registry_object id="oval:org.mitre.oval:obj:15263" version="1" comment="The registry key that identifies the location of the Word Viewer installed directory." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <hive>HKEY_LOCAL_MACHINE</hive>
      <key>SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wordview.exe</key>
      <name>Path</name>
    </registry_object>
  </objects>
  <states>
    <registry_state id="oval:org.mitre.oval:ste:6423" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="version">9.00.3042.00</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>10.2.5110</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:4586" version="1" comment="Regex that matches a string containing numbers separated by a hyphen" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">.[0-9]+-.[0-9]+-.[0-9]+-.[0-9]+$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2179" version="3" comment="Regex that matches a string containing -OEM-" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^.*-OEM-.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:4310" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="version" operation="greater than">9.0.0.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:449" version="3" comment="Regex that matches a string beginning with 11." xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^11\..+$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:3218" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int" operation="greater than">0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:4777" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">2</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:4255" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6844.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:3438" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">12.0.6325.5000</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:4393" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.8230.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:17994" version="1" comment="State matches if version is less than 2005.90.3073.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2005.90.3073.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:18247" version="1" comment="State matches if version is less than 2005.90.3282.0" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2005.90.3282.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:12246" version="1" comment="State matches if lower version of Wireshark is installed on the system" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Ethereal.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:5622" version="2" comment="State matches if higher version of Wireshark is installed on the system" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^Wireshark.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:11861" version="1" comment="The registry key matches with version of the Wireshark 1.2.0 to 1.2.9" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^(1\.2\.[0-9])$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:710" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.1.0.12512</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:12296" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than or equal">5.5.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1078" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">5.6.0.8831</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1258" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.70.11.40</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1257" version="1" deprecated="true" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals" datatype="binary">1</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:1445" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="greater than">6.0.0.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1444" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">6.1.0.211</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:1448" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.5709.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:1447" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">10.0.4333.0</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:1446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value>10.0.6626.0</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2267" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.5815.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2280" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.1.9904</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2294" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.5815.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2328" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8216</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2365" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.9716</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2366" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">8.0.0.9315</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2397" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.747.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2396" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2000.80.747.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2408" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.70.11.46</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2407" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">3.70.11.46</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2406" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:377" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.1.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:376" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.12.5118.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2514" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8216</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2538" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.6.*$</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:2537" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.62.9119.1</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:446" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">2.53.6202.0</version>
    </file_state>
    <registry_state id="oval:org.mitre.oval:ste:2536" version="2" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value datatype="int">1</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:2409" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="pattern match">^2\.5.*$</value>
    </registry_state>
    <registry_state id="oval:org.mitre.oval:ste:451" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <value operation="equals">9.00.9327</value>
    </registry_state>
    <file_state id="oval:org.mitre.oval:ste:535" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">9.0.0.8929</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:561" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">10.0.6754.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:639" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.6502.0</version>
    </file_state>
    <file_state id="oval:org.mitre.oval:ste:2474" version="1" xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#windows">
      <version datatype="version" operation="less than">11.0.6506.0</version>
    </file_state>
  </states>
  <variables>
    <local_variable id="oval:org.mitre.oval:var:868" version="1" comment="Microsoft PowerPoint Viewer folder in Program Files" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Microsoft Office\PowerPoint Viewer</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:713" version="1" comment="The shared Office XP directory" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\OFFICE10</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:553" version="1" comment="The shared Office 2007 directory" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\Microsoft Shared\OFFICE12</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:107" version="1" comment="Office11 folder in Program Files" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Microsoft Office\Office11</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:678" version="2" comment="MS SQL Server 2005 instance directories" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:12103"/>
        <literal_component>\Binn</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:154" version="1" comment="Microsoft SQL Server 2005 Tools - path" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\Microsoft SQL Server\90\Tools\Binn\VSShell\Common7\IDE</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:246" datatype="string" comment="MSN Messenger directory" version="1">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:309"/>
        <literal_component>\MSN Messenger</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:247" version="1" comment="Outlook.exe App Path directory" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:1071"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:231" version="1" comment="Excel installation directory" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:663"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:200" version="1" comment="Windows System32 directory" datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:219"/>
        <literal_component>\System32</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:212" version="2" comment="The path to the msadc directory under the the program files directory." datatype="string">
      <concat>
        <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:281"/>
        <literal_component>\System\msadc</literal_component>
      </concat>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:221" version="1" comment="Word install directory" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:493"/>
    </local_variable>
    <local_variable id="oval:org.mitre.oval:var:1946" version="1" comment="Word install directory" datatype="string">
      <object_component item_field="value" object_ref="oval:org.mitre.oval:obj:15263"/>
    </local_variable>
  </variables>
</oval_definitions>
